Pyup maintains a narrow set of tools focused on Python dependency analysis and security scanning, including its dependency parser and Safety vulnerability checker, which support development workflows and supply-chain risk assessment. The observed vulnerability classes center on input-handling and resource-consumption weaknesses, including inefficient regular expression complexity and reliance on untrusted inputs in security decisions, which reflect the parsing demands inherent to dependency analysis. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pyup over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39280HIGH dparse is a parser for Python dependency files. dparse in versions before 0.5.2 contain a regular expression that is vulnerable to a Regular Expression Denial of Service. All the u | Oct 6, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-5252MEDIUM The command-line "safety" package for Python has a potential security issue. There are two Python characteristics that allow malicious code to “poison-pill” command-line Safety pac | Mar 23, 2020 | 4.1 | 13 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pyup.
Media articles that mention a CVE ID that affects a product developed by Pyup — matched by CVE ID, not by vendor name.