Security Risk Category

Python Security Risks

Published vulnerability pages connected to Python. Each page keeps one canonical URL and focused remediation guidance.

59 published Python risks

Python risks

Showing 1–36 of 59 published risks.

high

CVE-2026-65908 PyCharm vulnerability

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open

CVE-2026-65908pythondevopssupply-chainremote-code-execution

Updated Jul 24, 2026

high

CVE-2026-16796 bedrock-agentcore 1.18.1 vulnerability

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to the patched version 1.18.1.

CVE-2026-16796python

Updated Jul 24, 2026

medium

CVE-2026-54422 Ironic Python Agent vulnerability

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.

CVE-2026-54422pythoninformation-disclosure

Updated Jul 24, 2026

high

CVE-2026-66138 Ironic Python Agent vulnerability

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.

CVE-2026-66138pythonremote-code-execution

Updated Jul 24, 2026

high

CVE-2026-8169 Switch Engine (EXOS) vulnerability

ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated using an insufficiently random source, which under certain conditions may allow an attacker to predict the expected response and activate debug-mode without authorization. Depending on device configuration and version, this may enable escalation to root-level access and persistent modification of the device software stack. Exploitation requires either a valid low-privilege account on the device (remote scenario) or physical serial console access (local scenario). This vulnerability is distinct from CVE-2017-14329, which addressed a different issue involving Python script privileges. Extreme would like to thank Hadrien Barral (Université Gustave Eiffel) and Georges-Axel Jaloyan (French Ministry of the Interior) for responsible disclosure of their findings.

CVE-2026-8169python

Updated Jul 21, 2026

highEPSS 0.003

CVE-2026-52869 mcp python sdk vulnerability

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2, the SSE and stateful Streamable HTTP transports mcp.server.sse.SseServerTransport and mcp.server.streamable_http_manager.StreamableHTTPSessionManager route requests to existing sessions using only the session_id query parameter or Mcp-Session-Id header without verifying the authenticated principal that created the session, allowing a different bearer-token-authenticated client with a known session ID to inject JSON-RPC messages into that session. This issue is fixed in version 1.27.2.

CVE-2026-52869pythonidor

Updated Jul 19, 2026

highEPSS 0.002

CVE-2026-52870 mcp python sdk vulnerability

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 until 1.27.2, default handlers installed by server.experimental.enable_tasks() for tasks/list, tasks/get, tasks/result, and tasks/cancel operate only on task identifiers without recording the session that created each task, allowing any connected client to enumerate, read results from, consume messages for, or cancel other clients' tasks. This issue is fixed in version 1.27.2.

CVE-2026-52870pythonauthorization-bypass

Updated Jul 19, 2026

highEPSS 0.002

CVE-2026-59950 mcp python sdk vulnerability

The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no SDK-level way to restrict which origins could connect to applications that exposed that transport. This issue is fixed in version 1.28.1.

CVE-2026-59950python

Updated Jul 19, 2026

highEPSS 0.003

CVE-2026-56259 Crawl4AI Credential Exfiltration Vulnerability

Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by supplying a malicious base_url parameter and setting api_token to env:VARIABLE_NAME to exfiltrate provider API keys and server secrets including JWT SECRET_KEY for authentication bypass.

CVE-2026-56259pythonapi-securityauthentication-bypassinformation-disclosure

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-56260 Crawl4AI Arbitrary File Write Vulnerability

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the application's user, overwriting server files and causing denial of service.

CVE-2026-56260pythonapi-securitydenial-of-servicepath-traversal

Updated Jul 15, 2026

high

CVE-2026-24240 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24240pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

high

CVE-2026-24242 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

CVE-2026-24242pythonlinuxdevopsinformation-disclosure

Updated Jul 15, 2026

high

CVE-2026-24243 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24243pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

high

CVE-2026-24244 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24244pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

high

CVE-2026-24245 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24245pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-24246 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24246pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-24247 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24247pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-24248 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24248pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-24249 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24249pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-24250 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24250pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-24251 in NVIDIA Megatron Bridge

NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

CVE-2026-24251pythonlinuxdevopsremote-code-execution

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-58065 in Apache Airflow Providers Git

The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or injecting malicious repository content. Deployments that use the Git DAG bundle or Git provider to clone over SSH with a deploy key are affected. The fix changes the default to verify host keys; upgrade to apache-airflow-providers-git `0.4.1` or later and configure a `known_hosts` file.

CVE-2026-58065pythonnetwork-securitydevopssupply-chain

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-59245 in Apache Airflow Providers FAB

In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers when a DAG named `DAGs` exists and a lower-privileged user is given per-DAG access to it, granting that user read/edit access to every DAG. Users are advised to upgrade to `apache-airflow-providers-fab` 3.7.2 or later, which disambiguates the resource-name collision.

CVE-2026-59245pythondevopsauthorization-bypassprivilege-escalation

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-62240 in CrewAI

CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS rebinding techniques to access internal services and cloud metadata endpoints.

CVE-2026-62240pythoninput-validationssrf

Updated Jul 15, 2026

medium

CVE-2026-59198 in Pillow

Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.

CVE-2026-59198pythoninformation-disclosurememory-corruption

Updated Jul 15, 2026

high

CVE-2026-59199 in Pillow

Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.

CVE-2026-59199pythoninput-validationmemory-corruption

Updated Jul 15, 2026

medium

CVE-2026-59203 in Pillow

Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing a crafted EPS file to cause Image.open() to seek backwards to the same directive and parse it repeatedly in an infinite loop. This issue is fixed in version 12.3.0.

CVE-2026-59203pythoninput-validationdenial-of-service

Updated Jul 15, 2026

high

CVE-2026-59204 in Pillow

Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.

CVE-2026-59204pythoninput-validationdenial-of-service

Updated Jul 15, 2026

high

CVE-2026-59205 in Pillow

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform's declared output mode. This issue is fixed in version 12.3.0.

CVE-2026-59205pythonapi-securityinput-validationmemory-corruption

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-57516 in Ray

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_decoder() function in webdataset_datasource.py unconditionally calls pickle.loads() on tar entries with .pkl/.pickle extensions and torch.load() with weights_only=False on .pt/.pth entries, executing arbitrary code inside Ray remote workers on every worker that processes the malicious archive.

CVE-2026-57516pythonremote-code-executionunsafe-deserialization

Updated Jul 15, 2026

highEPSS 0.007

CVE-2026-49119 in Gradio

Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths. Attackers can provide crafted path segments that cause os.path.join to discard the root_dir prefix entirely, resulting in arbitrary file read or exposure of sensitive files outside the intended directory.

CVE-2026-49119pythonweb-applicationinformation-disclosurepath-traversal

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-54259 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly listed items for which the user has not been granted choose permission. A user with access to the Wagtail admin could see the filename and name and URLs of documents and images in those collections. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54259pythonweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-54260 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an authenticated admin user can trigger expensive rendition processing with purposefully crafted filter specs resulting in potentially service degradation. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54260pythonweb-applicationdenial-of-service

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-54261 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any image. The existing data of the image object itself is not exposed. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54261pythonweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 14, 2026

mediumEPSS 0.002

CVE-2026-54262 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54262pythonweb-applicationauthorization-bypass

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-54263 in Wagtail

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflected cross-site scripting (XSS) vulnerability exists on the dynamic image URL generator view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could craft a URL that, when viewed by a user with higher privileges, could perform actions with that user's credentials. The vulnerability is present for all sites, even if they do not enable the dynamic image serve view. The vulnerability is not exploitable by an ordinary site visitor without access to the Wagtail admin. This issue has been fixed in versions 7.0.8, 7.3.3, and 7.4.2.

CVE-2026-54263pythonweb-applicationxss

Updated Jul 14, 2026