Security Audits

PyPI Package Security Audits

Sherlock Forensics maintains security audit reports for 17 popular PyPI packages. A total of 639 known vulnerabilities are catalogued across these packages as of 2026-09-19. Each report includes CVE details and remediation guidance.

Package Latest Version Vulnerabilities Description
Django 6.1.1 321 A high-level Python web framework that encourages rapid development and clean, pragmatic design.
Pillow 12.3.0 153 Python Imaging Library (fork)
cryptography 50.0.1 42 cryptography is a package which provides cryptographic recipes and primitives to Python developers.
Scrapy 2.19.0 23 A high-level Web Crawling and Web Scraping framework
Jinja2 3.1.6 20 A very fast and expressive template engine.
Requests 2.34.2 16 Python HTTP for Humans.
NumPy 2.5.3 16 Fundamental package for array computing in Python
Paramiko 5.0.0 12 SSH2 protocol library
Flask 3.1.3 10 A simple framework for building complex web applications.
SQLAlchemy 2.0.54 6 Database Abstraction Library
Gunicorn 26.2.0 6 WSGI HTTP Server for UNIX
SciPy 1.18.1 4 Fundamental algorithms for scientific computing in Python
Pydantic 2.13.5 4 Data validation using Python type hints
FastAPI 0.141.1 3 FastAPI framework, high performance, easy to learn, fast to code, ready for production
pytest 9.1.1 2 pytest: simple powerful testing with Python
Pandas 3.0.6 1 Powerful data structures for data analysis, time series, and statistics
Boto3 1.43.98 0 The AWS SDK for Python (Boto3)

Audit Your Dependencies

Our vibe coding security audit scans your entire dependency tree for vulnerable packages, misconfigurations and exposed secrets.

Get a Security Audit