pyod
A Python library for anomaly detection across tabular, time series, graph, text, image, and audio data. 60+ detectors, benchmark-backed ADEngine orchestration, and an agentic workflow for AI agents.
Activity
- Latest release
- 4w ago
- Total releases
- 116
- Cadence
- ~24 days
- Last 12 months
- 19
Reach
- Stars
- 10.0k
Details
- License
- BSD-2-Clause
- First release
- May 20, 2018
| Version | Released | |
|---|---|---|
3.6.5
patch
| ||
3.6.4
patch
| ||
3.6.3
patch
| ||
3.6.2
patch
| ||
3.6.1
patch
1 CVE
CVE-2026-15529
PYSEC-2026-3909
GHSA-997v-r4v7-9f3g
Sep 10, 2026
PyOD persistence.load deserializes untrusted artifacts before validation
Medium
Network
Low
Low
None
A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The pull request to fix this issue requires some minor changes. Affected versions
3.5.0
3.5.1
3.5.2
3.5.4
3.6.0
3.6.1
Fixed in
3.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.6.0
minor
1 CVE
CVE-2026-15529
PYSEC-2026-3909
GHSA-997v-r4v7-9f3g
Sep 10, 2026
PyOD persistence.load deserializes untrusted artifacts before validation
Medium
Network
Low
Low
None
A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The pull request to fix this issue requires some minor changes. Affected versions
3.5.0
3.5.1
3.5.2
3.5.4
3.6.0
3.6.1
Fixed in
3.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.5.4
patch
1 CVE
CVE-2026-15529
PYSEC-2026-3909
GHSA-997v-r4v7-9f3g
Sep 10, 2026
PyOD persistence.load deserializes untrusted artifacts before validation
Medium
Network
Low
Low
None
A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The pull request to fix this issue requires some minor changes. Affected versions
3.5.0
3.5.1
3.5.2
3.5.4
3.6.0
3.6.1
Fixed in
3.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.5.2
patch
1 CVE
CVE-2026-15529
PYSEC-2026-3909
GHSA-997v-r4v7-9f3g
Sep 10, 2026
PyOD persistence.load deserializes untrusted artifacts before validation
Medium
Network
Low
Low
None
A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The pull request to fix this issue requires some minor changes. Affected versions
3.5.0
3.5.1
3.5.2
3.5.4
3.6.0
3.6.1
Fixed in
3.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.5.1
patch
1 CVE
CVE-2026-15529
PYSEC-2026-3909
GHSA-997v-r4v7-9f3g
Sep 10, 2026
PyOD persistence.load deserializes untrusted artifacts before validation
Medium
Network
Low
Low
None
A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The pull request to fix this issue requires some minor changes. Affected versions
3.5.0
3.5.1
3.5.2
3.5.4
3.6.0
3.6.1
Fixed in
3.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.5.0
minor
1 CVE
CVE-2026-15529
PYSEC-2026-3909
GHSA-997v-r4v7-9f3g
Sep 10, 2026
PyOD persistence.load deserializes untrusted artifacts before validation
Medium
Network
Low
Low
None
A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remotely. The pull request to fix this issue requires some minor changes. Affected versions
3.5.0
3.5.1
3.5.2
3.5.4
3.6.0
3.6.1
Fixed in
3.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
3.4.0
minor
| ||
3.3.0
minor
| ||
3.2.1
patch
| ||
3.2.0
minor
| ||
3.1.0
minor
| ||
3.0.0
major
| ||
2.1.0
minor
| ||
2.0.7
patch
| ||
2.0.6
patch
| ||
2.0.5
patch
| ||
2.0.4
patch
| ||
2.0.3
patch
| ||
2.0.2
patch
| ||
2.0.1
patch
| ||
2.0.0
major
| ||
1.1.3
patch
| ||
1.1.2
patch
| ||
1.1.1
patch
| ||
1.1.0
minor
| ||
1.0.9
patch
| ||
1.0.8
patch
| ||
1.0.7
patch
| ||
1.0.6
patch
| ||
1.0.5
patch
| ||
1.0.4
patch
| ||
1.0.3
patch
| ||
1.0.2
patch
| ||
1.0.1
patch
| ||
1.0.0
major
| ||
0.9.9
patch
| ||
0.9.8
patch
| ||
0.9.7
patch
| ||
0.9.6
patch
| ||
0.9.5
patch
| ||
0.9.4
patch
| ||
0.9.3
patch
| ||
0.9.2
patch
| ||
0.9.1
patch
| ||
0.9.0
minor
| ||
0.8.9
patch
|