Skip to content

Package advisories

PyPI

211advisory rows165advisories84packagesRSSas of the 2026-09-07 snapshot

An advisory is the GHSA entry a Dependabot alert links to; GitHub-reviewed only. One row is one change to one package: 26 fixed-in version changed, 185 package added later.

No rate: 35,259 advisories were compared across every ecosystem together, and the analysis carries no count of how many were PyPI, so nothing here divides one number by the other.

Kind of change

185 counted rows in this one change · showing 1 to 50 · newest advisory first

One change, in full: Package added to advisory: 67 packages named as affected in pypi. The same change, 185 rows across 139 advisories. Back to pypi

Changes to GitHub-reviewed advisories naming a package in pypi. Each row gives the kind of change and the advisory it happened to. Where the same change was made to several advisories or packages at once, one row stands for all of them, says how many, and opens to every one. Then the ecosystem and package, what the advisory said beside what it says now, GitHub's severity level, and the date the advisory was published.
Package, The package the change names, or where one row stands for the same change across several packages, how many.Kind of changeAdvisory, The advisory id, or where one row stands for the same change made to several advisories, how many it stands for. An advisory id links to GitHub, and a CVE id is shown beside it where the advisory names one.What changedSeverity, GitHub's severity level for the advisory as it stands today: low, moderate, high or critical. Where one row stands for advisories at more than one level, it says how many levels, never one of them.Advisory published, The date the advisory was published. Every lag on this source is measured from it, and it is a third clock beside the CVE catalog's publication date and the date CISA added an entry to KEV. Two kinds of change also carry a date of their own: a withdrawal states its own timestamp, and a changed fix version is dated by reading back through the dated saves of the advisory file until the one where the version first reached the value it has today. A package added and a severity changed leave no commit of their own to date, so for those the date of the change is not recorded at all. That is absence, never same-day.
pyasn1Package added to advisoryGHSA-m4p7-r5rc-7g4jCVE-2026-59884not named as affected when the advisory was published, now names pyasn1high2026-07-21
py-rattlerPackage added to advisoryGHSA-q53q-5r4j-5729CVE-2026-47425not named as affected when the advisory was published, now names py-rattlermoderate2026-06-01
openc3Package added to advisoryGHSA-ffq5-qpvf-xq7xCVE-2026-42086not named as affected when the advisory was published, now names openc3moderate2026-04-22
apache-airflowPackage added to advisoryGHSA-w9r4-94fj-xp69CVE-2026-32690not named as affected when the advisory was published, now names apache-airflowlow2026-04-18
mlflowPackage added to advisoryGHSA-rvhj-8chj-8v3cCVE-2026-0596not named as affected when the advisory was published, now names mlflowcritical2026-03-31
openhands-aiPackage added to advisoryGHSA-7h8w-hj9j-8rjwCVE-2026-33718not named as affected when the advisory was published, now names openhands-aihigh2026-03-25
msmcp-azurePackage added to advisoryGHSA-hhfx-wfvq-7g9cCVE-2026-26118not named as affected when the advisory was published, now names msmcp-azurehigh2026-03-10
langflowPackage added to advisoryGHSA-c5cp-vx83-jhqxCVE-2026-21445not named as affected when the advisory was published, now names langflowhigh2026-01-02
hdwalletPackage added to advisoryGHSA-mrfv-m5wm-5w6wCVE-2025-69277not named as affected when the advisory was published, now names hdwalletmoderate2025-12-31
pynaclPackage added to advisoryGHSA-mrfv-m5wm-5w6wCVE-2025-69277not named as affected when the advisory was published, now names pynaclmoderate2025-12-31
scrapyPackage added to advisoryGHSA-2qfp-q593-8484CVE-2025-6176not named as affected when the advisory was published, now names scrapyhigh2025-10-31
pysparkPackage added to advisoryGHSA-6p6v-m64v-jx8qCVE-2025-55039not named as affected when the advisory was published, now names pysparklow2025-10-15
apache-iotdbPackage added to advisoryGHSA-776q-jw43-fhjxCVE-2025-48459not named as affected when the advisory was published, now names apache-iotdbcritical2025-09-24
langflow-basePackage added to advisoryGHSA-rvqx-wpfh-mfx7CVE-2025-3248not named as affected when the advisory was published, now names langflow-basecritical2025-06-17
apache-iotdbPackage added to advisoryGHSA-5fc3-pqf2-57cxCVE-2025-26864not named as affected when the advisory was published, now names apache-iotdbmoderate2025-05-14
apache-iotdbPackage added to advisoryGHSA-f4rq-f4j9-f6rmCVE-2024-24780not named as affected when the advisory was published, now names apache-iotdbcritical2025-05-14
llama-index-packs-finchatPackage added to advisoryGHSA-x48g-hm9c-ww42CVE-2024-12909not named as affected when the advisory was published, now names llama-index-packs-finchatcritical2025-03-20
llama-index-corePackage added to advisoryGHSA-j3wr-m6xh-64hgCVE-2024-12704not named as affected when the advisory was published, now names llama-index-corehigh2025-03-20
streampipesPackage added to advisoryGHSA-vm7w-2724-5m23CVE-2024-24778not named as affected when the advisory was published, now names streampipesmoderate2025-03-03
starlitePackage added to advisoryGHSA-gjcc-jvgw-wvwjCVE-2024-52581not named as affected when the advisory was published, now names starlitehigh2024-11-20
langchain-communityPackage added to advisoryGHSA-45pg-36p6-83v9CVE-2024-8309not named as affected when the advisory was published, now names langchain-communitylow2024-10-29
openc3Package added to advisoryGHSA-4xqv-47rm-37mmCVE-2024-47529not named as affected when the advisory was published, now names openc3moderate2024-10-02
openc3Package added to advisoryGHSA-8jxr-mccc-mwg8CVE-2024-46977not named as affected when the advisory was published, now names openc3high2024-10-02
openc3Package added to advisoryGHSA-vfj8-5pj7-2f9gCVE-2024-43795not named as affected when the advisory was published, now names openc3moderate2024-10-02
langchain-communityPackage added to advisoryGHSA-f2jm-rw3h-6phgCVE-2024-5998not named as affected when the advisory was published, now names langchain-communityhigh2024-09-17
ansible-corePackage added to advisoryGHSA-jpxc-vmjf-9fcjCVE-2024-8775not named as affected when the advisory was published, now names ansible-corehigh2024-09-16
ekuiperPackage added to advisoryGHSA-r5ph-4jxm-6j9pCVE-2024-43406not named as affected when the advisory was published, now names ekuiperhigh2024-08-20
streampipesPackage added to advisoryGHSA-6523-jf4r-c962CVE-2024-31411not named as affected when the advisory was published, now names streampipeshigh2024-07-17
streampipesPackage added to advisoryGHSA-2qph-v9p2-q2gvCVE-2024-30471not named as affected when the advisory was published, now names streampipesmoderate2024-07-17
streampipesPackage added to advisoryGHSA-9gr7-gh74-qg9xCVE-2024-31979not named as affected when the advisory was published, now names streampipesmoderate2024-07-17
django-tinymcePackage added to advisoryGHSA-9hcv-j9pv-qmphCVE-2024-38356not named as affected when the advisory was published, now names django-tinymcemoderate2024-06-19
django-tinymcePackage added to advisoryGHSA-w9jx-4g6g-rp7xCVE-2024-38357not named as affected when the advisory was published, now names django-tinymcemoderate2024-06-19
apache-submarinePackage added to advisoryGHSA-6q97-8v3g-rpxwCVE-2024-36265not named as affected when the advisory was published, now names apache-submarinecritical2024-06-12
apache-submarinePackage added to advisoryGHSA-jwcg-wv5x-vg3gCVE-2024-36264not named as affected when the advisory was published, now names apache-submarinemoderate2024-06-12
langchain-communityPackage added to advisoryGHSA-3hjh-jh2h-vrg6CVE-2024-2965not named as affected when the advisory was published, now names langchain-communitymoderate2024-06-06
langchain-communityPackage added to advisoryGHSA-q25c-c977-4cmhCVE-2024-3095not named as affected when the advisory was published, now names langchain-communitymoderate2024-06-06
langchain-corePackage added to advisoryGHSA-h59x-p739-982cCVE-2024-28088not named as affected when the advisory was published, now names langchain-corelow2024-03-04
apache-iotdbPackage added to advisoryGHSA-rxgg-273w-rfw7CVE-2023-46226not named as affected when the advisory was published, now names apache-iotdbhigh2024-01-15
appwritePackage added to advisoryGHSA-g777-crp9-m27gCVE-2023-50974not named as affected when the advisory was published, now names appwritemoderate2024-01-09
paramikoPackage added to advisoryGHSA-45x7-px36-x8w8CVE-2023-48795not named as affected when the advisory was published, now names paramikomoderate2023-12-18
apache-dolphinschedulerPackage added to advisoryGHSA-4vvc-r4p4-qgrrCVE-2023-48796not named as affected when the advisory was published, now names apache-dolphinschedulerhigh2023-11-24
vantage6-nodePackage added to advisoryGHSA-vc3v-ppc7-v486CVE-2023-47631not named as affected when the advisory was published, now names vantage6-nodehigh2023-11-14
pillowPackage added to advisoryGHSA-j7hp-h8jx-5pprCVE-2023-4863not named as affected when the advisory was published, now names pillowhigh2023-09-12
numexprPackage added to advisoryGHSA-f73w-4m7g-ch9xCVE-2023-39631not named as affected when the advisory was published, now names numexprcritical2023-09-01
apache-iotdbPackage added to advisoryGHSA-pvjv-386f-c8whCVE-2023-24831not named as affected when the advisory was published, now names apache-iotdbcritical2023-04-17
pysparkPackage added to advisoryGHSA-329j-jfvr-rhr6CVE-2023-22946not named as affected when the advisory was published, now names pysparkcritical2023-04-17
zstdPackage added to advisoryGHSA-5c9c-6x87-f9vmCVE-2022-4899not named as affected when the advisory was published, now names zstdhigh2023-03-31
apache-airflow-providers-apache-hivePackage added to advisoryGHSA-cm43-f2pv-6v68CVE-2022-41131not named as affected when the advisory was published, now names apache-airflow-providers-apache-hivehigh2022-11-22
tensorflowPackage added to advisoryGHSA-h6q3-vv32-2cq5CVE-2022-41894not named as affected when the advisory was published, now names tensorflowhigh2022-11-21
pysparkPackage added to advisoryGHSA-43xg-8wmj-cw8hCVE-2022-31777not named as affected when the advisory was published, now names pysparkmoderate2022-11-01

Every change counted from this source is on this page, so an advisory with no row here had no change of that kind. No finding here is not an all clear. It means this check found nothing in the history it can see, not that nothing happened.

A grouped row is the same change, repeated: where one change was made to many packages or advisories, the advisory column says how many it stands for and opens to every one. The change is identical; it was not necessarily made in one act.

A fixed-in version is compared within one release branch: an advisory listing a fix for 4.1.x and another for 4.2.x states two, and taking the highest version across the package would report a newly added branch as though an existing branch's fix had changed.

37 more advisories that name a package in pypi had the severity changed, or the whole advisory withdrawn. None of it is counted in any figure above. Open to read it.

A severity level and a withdrawal belong to the whole advisory. The advisory database records neither against a package, so neither can be attributed to an ecosystem. These 37 rows are here for one reason: the same advisory also names a package in pypi in the table above. The other 3,143 of the 3,180 cannot be placed in an ecosystem at all.

Severity changes and withdrawals recorded against advisories that also name a package in pypi. These rows name no ecosystem of their own and are not counted in this page's ecosystem figures.
Kind of changeAdvisoryWhat changedSeverityAdvisory published
Advisory severity changedGHSA-6p6v-m64v-jx8qCVE-2025-55039stated at publication MODERATE, now states LOWA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.low2025-10-15
Advisory severity changedGHSA-776q-jw43-fhjxCVE-2025-48459stated at publication HIGH, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.critical2025-09-24
Advisory severity changedGHSA-f2jm-rw3h-6phgCVE-2024-5998stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.high2024-09-17
Advisory severity changedGHSA-jpxc-vmjf-9fcjCVE-2024-8775stated at publication MODERATE, now states HIGHThe severity label changed while the stated CVSS vectors stayed the same.high2024-09-16
Advisory severity changedGHSA-vf7j-cmrj-pmmmCVE-2024-25723stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2024-02-27
Advisory severity changedGHSA-rxgg-273w-rfw7CVE-2023-46226stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2024-01-15
Advisory severity changedGHSA-4vvc-r4p4-qgrrCVE-2023-48796stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2023-11-24
Advisory severity changedGHSA-j7hp-h8jx-5pprCVE-2023-4863stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2023-09-12
Advisory severity changedGHSA-f73w-4m7g-ch9xCVE-2023-39631stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.critical2023-09-01
Advisory severity changedGHSA-pvjv-386f-c8whCVE-2023-24831stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.critical2023-04-17
Advisory severity changedGHSA-329j-jfvr-rhr6CVE-2023-22946stated at publication MODERATE, now states CRITICALA vector changed on a shared CVSS version. The band and vector edits may have occurred separately.critical2023-04-17
Advisory severity changedGHSA-cm43-f2pv-6v68CVE-2022-41131stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-11-22
Advisory severity changedGHSA-43xg-8wmj-cw8hCVE-2022-31777stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.moderate2022-11-01
Advisory severity changedGHSA-g6hg-4v3c-6jq7CVE-2022-43766stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-10-26
Advisory severity changedGHSA-9jmq-rx5f-8jwqCVE-2021-32862stated at publication HIGH, now states MODERATENo CVSS vector was stated in the first observed version.moderate2022-08-10
Advisory severity changedGHSA-m43h-hfrq-x8wxCVE-2022-26477stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-06-28
Advisory severity changedGHSA-rqg8-xjp2-pg9wCVE-2019-12887stated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.critical2022-05-24
Advisory severity changedGHSA-27px-qpmj-qg38CVE-2012-0878stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-05-17
Advisory severity changedGHSA-4j5j-58j7-6c3wCVE-2014-9706stated at publication HIGH, now states CRITICALNo CVSS vector was stated in the first observed version.critical2022-05-17
Advisory severity changedGHSA-7f2c-vp52-gmfwCVE-2014-7144stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-05-17
Advisory severity changedGHSA-984m-rj28-8c6xCVE-2015-7315stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.high2022-05-17
Advisory severity changedGHSA-mffc-9gx5-99g3CVE-2015-3206stated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.critical2022-05-14
Advisory severity changedGHSA-vpqp-hx68-p2wxCVE-2013-2217stated at publication LOW, now states MODERATENo CVSS vector was stated in the first observed version.moderate2022-05-14
Advisory severity changedGHSA-hhx9-4vw2-x54rCVE-2015-0260stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-05-13
Advisory severity changedGHSA-x634-34m9-96mpCVE-2018-14635stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.high2022-05-13
Advisory severity changedGHSA-qg5x-66hp-cw5pCVE-2022-25598stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-03-31
Advisory severity changedGHSA-9rr6-jpg7-9jg6CVE-2021-38296stated at publication MODERATE, now states HIGHNo CVSS vector was stated in the first observed version.high2022-03-11
Advisory severity changedGHSA-h4pc-gx2w-f2xvCVE-2021-29606stated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same.moderate2021-05-21
Advisory severity changedGHSA-jf7h-7m85-w2v2CVE-2021-29605stated at publication HIGH, now states MODERATEA CVSS version was added; the existing vectors stayed the same.moderate2021-05-21
Advisory severity changedGHSA-hx2x-85gr-wrpqCVE-2020-15212stated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.critical2020-09-25
Advisory severity changedGHSA-p2cq-cprg-frvmCVE-2020-15214stated at publication HIGH, now states CRITICALA CVSS version was added; the existing vectors stayed the same.critical2020-09-25
Advisory severity changedGHSA-x9j7-x98r-r4w2CVE-2020-15210stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.high2020-09-25
Advisory severity changedGHSA-h98h-8mxr-m8gxCVE-2018-21233stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.high2020-05-13
Advisory severity changedGHSA-x64g-wjmw-w328CVE-2015-5306stated at publication MODERATE, now states CRITICALNo CVSS vector was stated in the first observed version.critical2019-07-05
Advisory severity changedGHSA-mfg7-x5m7-6p8wCVE-2019-9635stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.high2019-04-30
Advisory severity changedGHSA-jfq2-rj7f-9gvfCVE-2018-7576stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.high2019-04-24
Advisory severity changedGHSA-f6f2-pwrj-64h3CVE-2019-10868stated at publication MODERATE, now states HIGHA CVSS version was added; the existing vectors stayed the same.high2019-04-10

Data sources and quality

Every figure on this page counts rows keyed to a GitHub advisory, naming an ecosystem and a package; none counts CVE records or is added to the record counts elsewhere on this site. Rows, advisories and packages are three different numbers, never added.

Not checked: GitHub-reviewed advisories only. An advisory GitHub never reviewed, and an ecosystem it does not review, produce no row at all, so an ecosystem missing from these figures is not evidence that its advisories held.

How advisories are compared, in full →

Advisory data from the GitHub Advisory Database, used under CC-BY-4.0. Not affiliated with or endorsed by GitHub.

Shipped snapshot computed 2026-09-07 from catalog commit ed5547afbae2. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.