PyPI is the Python Package Index, a repository hosting thousands of third-party Python packages that serve as critical dependencies across data science, web development, and infrastructure automation. Vulnerabilities reported against PyPI-hosted packages skew strongly toward critical-severity outcomes, reflecting the supply-chain risk posed when widely imported libraries contain flaws in memory handling or bounds checking. The recurring weakness classes, dominated by out-of-bounds writes and NVD placeholder designations for packages with sparse disclosure detail, underscore the challenge of triaging security issues across a decentralized ecosystem of maintainers with varying security practices. Defenders should treat PyPI package advisories as high-priority, maintain visibility into transitive dependencies, and coordinate patching across upstream library updates; live severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pypi over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34055CRITICAL The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user inform | Jun 24, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-34054CRITICAL The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive us | Jun 24, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-33003CRITICAL The watools package in PyPI v0.0.1 to v0.0.8 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive us | Jun 24, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-33000CRITICAL The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive | Jun 24, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-34500CRITICAL The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party. | Jul 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-34056CRITICAL The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user info | Jun 24, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-33001CRITICAL The AAmiles package in PyPI v0.1.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user informa | Jun 24, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-32998CRITICAL The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to | Jun 24, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-32996CRITICAL The django-navbar-client package of v0.9.50 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sen | Jun 24, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-33004CRITICAL The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive u | Jun 24, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pypi.
Media articles that mention a CVE ID that affects a product developed by Pypi — matched by CVE ID, not by vendor name.