Python Poetry is a dependency-management and packaging tool for Python projects that, despite a narrow product scope centered on the Poetry tool and its Cleo command-line framework, occupies a significant position in the Python development supply chain. Vulnerabilities affecting the vendor reflect the parsing, input-handling, and package-resolution logic inherent to a build and dependency-management system; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Python Poetry over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26184CRITICAL Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directo | Mar 21, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-42966HIGH An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows meth | Nov 9, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-36069HIGH Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a registry, Poetry uses various commands, such as `git clone`. Thes | Sep 7, 2022 | 7.3 | 25 | NO | NO |
CVE-2022-36070HIGH Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes various commands, e.g. `git config`. These commands are being exe | Sep 7, 2022 | 7.3 | 24 | NO | NO |
CVE-2026-34591MEDIUM Poetry is a dependency manager for Python. From version 1.4.0 to before version 2.3.3, a crafted wheel can contain ../ paths that Poetry writes to disk without containment checks, | Apr 2, 2026 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Python Poetry.
Media articles that mention a CVE ID that affects a product developed by Python Poetry — matched by CVE ID, not by vendor name.