Anaconda maintains a narrowly scoped portfolio centered on its Python distribution and package management ecosystem, including Anaconda3, conda-build, and data-processing tools such as Dask that hold prominent positions in scientific computing and machine-learning development environments. The vendor's vulnerability profile skews strongly toward critical-severity outcomes and recurs through privilege-escalation and code-injection risks—including incorrect permission assignment, execution with unnecessary privileges, certificate validation flaws, and path-traversal weaknesses—that reflect the trust relationship between package managers and their users and the elevated permissions required by build and runtime tooling. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Anaconda over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42343CRITICAL An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters started with dask.distributed.LocalCluster or dask.distributed.Cli | Oct 26, 2021 | 9.8 | 31 | NO | NO |
CVE-2025-32800CRITICAL Conda-build contains commands and tools to build conda packages. Prior to version 25.3.0, the pyproject.toml lists conda-index as a Python dependency. This package is not published | Jun 16, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-32799CRITICAL Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build processing logic is vulnerable to path traversal (Tarslip) attacks due to | Jun 16, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-32798CRITICAL Conda-build contains commands and tools to build conda packages. Prior to version 25.4.0, the conda-build recipe processing logic has been found to be vulnerable to arbitrary code | Jun 16, 2025 | 9.8 | 27 | NO | NO |
CVE-2021-42969HIGH Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the u | May 13, 2022 | 8.8 | 26 | NO | NO |
CVE-2024-46060HIGH Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable | Dec 17, 2025 | 7.8 | 25 | NO | NO |
CVE-2022-26526HIGH Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory in | Mar 17, 2022 | 7.8 | 25 | NO | NO |
CVE-2026-23528MEDIUM Dask distributed is a distributed task scheduler for Dask. Prior to 2026.1.0, when Jupyter Lab, jupyter-server-proxy, and Dask distributed are all run together, it is possible to c | Jan 16, 2026 | 6.1 | 22 | NO | NO |
CVE-2025-32797HIGH Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, the write_build_scripts function in conda-build creates the temporary build script conda_b | Jun 16, 2025 | 7.0 | 21 | NO | NO |
CVE-2023-35845MEDIUM Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many fil | Sep 11, 2023 | 4.7 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Anaconda.
Media articles that mention a CVE ID that affects a product developed by Anaconda — matched by CVE ID, not by vendor name.