pypa
Security Risk Profile
44
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 28, 2013 to present
12
Total CVEs
6
Critical+High
0
Exploited
2
Unpatched
Threat Assessment
Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
44/100
medium
Severity Distribution
Critical
1High
5Medium
6Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
2Age Distribution
Common Weaknesses (CWE)
1
Input Validation
4
2
Path Traversal
3
3
Command Injection
2
4
Code Injection
1
5
OS Command Injection
1
Most Affected Products
1. pypa pip10
2. Fedoraproject Fedora8
3. pip/pip7
4. redhat/python-pip5
5. Oracle Communications Cloud Native Core Network Function Cloud Native Environment4
Recent Vulnerabilities
See more →CVE-2026-8643
CVSS 4.1EPSS 0%medium
pip can extract console_scripts and gui_scripts outside installation directory
4/22/2026
REDHAT-BUG-2460927
CVSS 7.0high
4/22/2026🔧 No Patch
REDHAT-BUG-2297771
CVSS 7.0high
7/15/2024🔧 No Patch
CVE-2023-5752
CVSS 5.5EPSS 0%medium
Mercurial configuration injectable in repo revision when installing via pip
10/24/2023
CVE-2022-21668
CVSS 9.3critical
Pipenv's requirements.txt parsing allows malicious index url in comments
1/10/2022
CVE-2021-3572
CVSS 5.7medium
4/24/2021
CVE-2018-20225
CVSS 7.8high
5/8/2020
CVE-2013-5123
CVSS 5.9medium
11/5/2019
CVE-2019-20916
CVSS 8.0high
4/16/2019
CVE-2014-8991
CVSS 6.2medium
10/9/2013
Monitor pypa in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.