Know every threat before it ships

200K+ vulnerabilities, malicious packages, and supply chain threats enriched with Corgea's research.

MEDIUM 6.5
PyPI

GHSA-8pcw-h6w9-h46g

plone.app.contenttypes has a Denial of Service in File Upload due to excessive filename length

MEDIUM 6.5
PyPI

CVE-2026-57576

plone.app.dexterity has a Denial of Service due to excessive title or description length

MEDIUM 6.5
PyPI

CVE-2026-78679

GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

MEDIUM 5.3
PyPI

CVE-2026-77249

MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup

MEDIUM 6.1
PyPI

CVE-2026-86062

lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content

MEDIUM 6.4
PyPI

CVE-2026-83805

Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs

MEDIUM 6.5
PyPI

CVE-2026-77266

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read and exfiltration via MCP tool call

MEDIUM 5.3
PyPI

CVE-2026-85709

lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses

MEDIUM 6.1
PyPI

CVE-2026-77250

MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions

MEDIUM 6.5
PyPI

CVE-2026-77270

MCP Atlassian: Arbitrary File Read via Upload Attachment Tools

MEDIUM 5.4
PyPI

CVE-2026-77272

MCP Atlassian: Reflected XSS in OAuth Setup Callback Handler

MEDIUM 5.4
PyPI

CVE-2026-91129

Home Assistant: mDNS Server-Side Request Forgery

MEDIUM 5.4
PyPI

CVE-2026-83801

Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text

MEDIUM 5.9
PyPI

CVE-2026-77265

MCP Atlassian: SSRF via DNS Rebinding in Header-Based Authentication Flow

MEDIUM 5.5
PyPI

CVE-2026-77268

MCP Atlassian: Insecure File Permissions on OAuth Token Storage

MEDIUM 5.9
PyPI

CVE-2026-85725

lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function

MEDIUM 6.5
PyPI

CVE-2026-77269

MCP Atlassian: Path traversal in upload_attachment allows arbitrary file read (incomplete fix for CVE-2026-27825)

MEDIUM 5.3
PyPI

CVE-2026-77528

Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation

MEDIUM 6.5
PyPI

CVE-2026-62282

OpenCVE: Server-Side Request Forgery (SSRF) in notifications

MEDIUM 5.5
PyPI

CVE-2026-56074

PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands

MEDIUM 6.6
PyPI

CVE-2025-51481

CVE-2025-51481

MEDIUM 6.5
PyPI

CVE-2026-73497

MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)

MEDIUM 5.3
PyPI

CVE-2026-86000

Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns

MEDIUM 5.3
PyPI

CVE-2026-85999

Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)

MEDIUM 5.3
PyPI

CVE-2023-41052

incorrect order of evaluation of side effects for some builtins

MEDIUM 6.5
PyPI

CVE-2026-69147

vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation

MEDIUM 6.8
PyPI

CVE-2026-77401

Zope AccessControl vulnerable to information disclosure through Python string `format` and `format_map` functions

MEDIUM 6.5
PyPI

CVE-2026-85078

sanic chunked trailer request smuggling allows hidden second request execution

MEDIUM 6.5
PyPI

CVE-2026-62949

AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPEN_CONFIRMATION

MEDIUM 6.5
PyPI

CVE-2026-57173

vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions

MEDIUM 6.3
PyPI

CVE-2026-61589

djust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live path

MEDIUM 6.5
PyPI

CVE-2026-61588

djust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the client

MEDIUM 6.5
PyPI

CVE-2024-58384

Tornado has a CRLF injection in CurlAsyncHTTPClient headers

MEDIUM 5.3
PyPI

CVE-2024-14029

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado

MEDIUM 5.9
PyPI

CVE-2026-91992

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

MEDIUM 6.3
PyPI

CVE-2026-12797

BerriAI litellm has Security Feature Bypass in BannedKeywords and AzureContentSafety Guardrails via call_type Mismatch on Async Endpoints

MEDIUM 4.3
PyPI

CVE-2026-12799

BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure

MEDIUM 6.3
PyPI

CVE-2026-12798

BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader

MEDIUM 6.3
PyPI

CVE-2026-12796

BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens

MEDIUM 4.3
PyPI

GHSA-vfm7-4h43-gp6m

Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service

MEDIUM 5.5
PyPI

CVE-2026-23679

CVE-2026-23679

MEDIUM 5.5
PyPI

CVE-2026-47104

CVE-2026-47104

MEDIUM 5.5
PyPI

CVE-2026-74871

CVE-2026-74871

MEDIUM 6.5
PyPI

CVE-2026-88006

Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange

MEDIUM 4.3
PyPI

CVE-2026-87012

Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value

MEDIUM 4.3
PyPI

CVE-2026-87013

Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle

MEDIUM 5.4
PyPI

CVE-2026-12770

LiteLLM: Admin Key Handler Has Improper Authorization

MEDIUM 6.5
PyPI

CVE-2026-87014

Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes

MEDIUM 6.8
PyPI

CVE-2026-87015

Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication

MEDIUM 5.0
PyPI

CVE-2026-12771

LiteLLM: M2M JWT Handler Has Improper Authorization

MEDIUM 6.3
PyPI

CVE-2026-12772

LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration

MEDIUM 4.3
PyPI

CVE-2026-87017

Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends

MEDIUM 4.3
PyPI

CVE-2026-87994

Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint

MEDIUM 6.5
PyPI

CVE-2026-88005

Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange

MEDIUM 4.3
PyPI

CVE-2026-87997

Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions

MEDIUM 6.5
PyPI

CVE-2026-73619

GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()

MEDIUM 6.1
PyPI

CVE-2026-32773

CVE-2026-32773

MEDIUM 5.4
PyPI

CVE-2026-73621

GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count

MEDIUM 5.3
PyPI

CVE-2026-81680

CVE-2026-81680

MEDIUM 6.5
PyPI

CVE-2026-12261

CVE-2026-12261

Ready to move

Start Securing

Free, no credit card | First findings in minutes