Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2248593
AlmaLinux
5959
Alpaquita
16087
Alpine
4608
Android
2912
Azure Linux
17651
BellSoft Hardened Containers
754
Bitnami
9341
Chainguard
1030980
CleanStart
3946
CRAN
14
crates.io
2739
Debian
68540
Docker Hardened Images
1
Echo
4006
GHC
3
GIT
107112
GitHub Actions
55
Go
9247
Hackage
33
Hex
364
Julia
1713
Linux
29269
Mageia
6232
Maven
7044
MinimOS
145036
npm
228905
NuGet
1869
opam
29
openEuler
8800
openSUSE
14484
OSS-Fuzz
4003
Packagist
7104
Pub
11
PyPI
25192
Red Hat
23387
Rocky Linux
4305
Root
19581
RubyGems
5326
SUSE
23349
SwiftURL
60
TuxCare
9776
Ubuntu
65637
VSCode
21
Wolfi
333108
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17325
PyPI/cleanup-string
Malicious code in cleanup-string (PyPI)
1 hour ago
No fix available
MAL-2026-17319
PyPI/bfox-build-utils
Malicious code in bfox-build-utils (PyPI)
2 hours ago
No fix available
GHSA-9j54-fg26-wv3r
PyPI/pyjwt
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
5 hours ago
Fix available
Severity - 7.4 (High)
GHSA-8wjv-2p76-3863
PyPI/pyjwt
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
5 hours ago
Fix available
Severity - 5.3 (Medium)
GHSA-hxm8-2xgr-2p9m
PyPI/pyjwt
PyJWT: Non-canonical signature segments enable raw-token revocation bypass
6 hours ago
Fix available
Severity - 4.8 (Medium)
GHSA-ffc3-869f-jxw9
PyPI/pyjwt
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
6 hours ago
Fix available
Severity - 9.1 (Critical)
GHSA-w2cx-738m-mc7w
PyPI/pyjwt
PyJWT accepts public JWK containers as HMAC secrets
6 hours ago
Fix available
Severity - 7.4 (High)
GHSA-9v7f-9g4p-ffgj
PyPI/pyjwt
PyJWT: PyJWKClient follows redirects when fetching JWKS
6 hours ago
Fix available
Severity - 7.4 (High)
GHSA-p4g4-x82p-q773
PyPI/pyjwt
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
6 hours ago
Fix available
Severity - 7.4 (High)
GHSA-r6x4-923q-g947
PyPI/pyjwt
PyJWT BOM Bypass
6 hours ago
Fix available
Severity - 7.4 (High)
GHSA-2gx3-rcp4-g85q
PyPI/pyjwt
PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
6 hours ago
Fix available
Severity - 5.3 (Medium)
MAL-2026-17286
PyPI/queeuees
Malicious code in queeuees (PyPI)
8 hours ago
No fix available
GHSA-w6j9-cwv2-h6wq
PyPI/pyjwt
PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
11 hours ago
Fix available
Severity - 5.9 (Medium)
GHSA-xpv3-w29h-x7cv
PyPI/oauthlib
Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)
11 hours ago
Fix available
Severity - 6.8 (Medium)
GHSA-hj66-6f7g-4r5v
PyPI/oauthlib
Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
11 hours ago
Fix available
Severity - 6.1 (Medium)
MAL-2026-17240
PyPI/aseitylab
Malicious code in aseitylab (PyPI)
yesterday
No fix available
Load more...
PyPI - OSV