Launch Week Day 1: Announcing Security Design Review
20 Total advisories
20 Vulnerabilities
0 Malware

Vulnerabilities

UNKNOWN
PyPI

CVE-2014-8991

CVE-2014-8991

LOW 3.3
PyPI

CVE-2023-5752

CVE-2023-5752

MEDIUM 5.5
PyPI

CVE-2026-8643

CVE-2026-8643

UNKNOWN
PyPI

CVE-2026-3219

pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files

UNKNOWN
PyPI

CVE-2026-6357

pip Vulnerable to Inclusion of Functionality from Untrusted Control Sphere

UNKNOWN
PyPI

CVE-2025-8869

pip's fallback tar extraction doesn't check symbolic links point to extraction directory

MEDIUM 5.7
PyPI

CVE-2021-3572

Improper Input Validation in pip

UNKNOWN
PyPI

CVE-2026-1703

pip Path Traversal vulnerability

MEDIUM 5.5
PyPI

CVE-2023-5752

Command Injection in pip when used with Mercurial

UNKNOWN
PyPI

CVE-2021-3572

CVE-2021-3572

MEDIUM 6.2
PyPI

CVE-2014-8991

pip lack of randomness in build directory

MEDIUM 5.9
PyPI

CVE-2013-5123

Improper Authentication in pip

HIGH 7.5
PyPI

CVE-2019-20916

Path Traversal in pip

MEDIUM 6.2
PyPI

CVE-2013-1888

Improper Link Resolution Before File Access in pip

HIGH 8.4
PyPI

CVE-2013-1629

Improper Input Validation in pip

UNKNOWN
PyPI

CVE-2019-20916

CVE-2019-20916

UNKNOWN
PyPI

CVE-2013-5123

CVE-2013-5123

UNKNOWN
PyPI

CVE-2013-1888

CVE-2013-1888

UNKNOWN
PyPI

CVE-2013-1629

CVE-2013-1629

UNKNOWN
PyPI

PYSEC-2020-192

PYSEC-2020-192

Ready to move

Start Securing

Free, no credit card | First findings in minutes