streamlit
A faster way to build and share data apps
Activity
- Latest release
- 1w ago
- Total releases
- 272
- Cadence
- ~13 days
- Last 12 months
- 19
Details
- License
- Apache-2.0
- First release
- Mar 20, 2018
| Version | Released | |
|---|---|---|
1.63.0
minor
|
1.63.0
minor
Dependencies (33)
+ 25 more |
|
1.62.0
minor
|
1.62.0
minor
Dependencies (34)
+ 26 more |
|
1.61.1
patch
|
1.61.1
patch
Dependencies (35)
+ 27 more |
|
1.61.0
minor
|
1.61.0
minor
Dependencies (35)
+ 27 more |
|
1.60.0
minor
|
1.60.0
minor
Dependencies (36)
+ 28 more |
|
1.59.2
patch
|
1.59.2
patch
Dependencies (37)
+ 29 more |
|
1.59.1
patch
|
1.59.1
patch
Dependencies (37)
+ 29 more |
|
1.59.0
minor
|
1.59.0
minor
Dependencies (36)
+ 28 more |
|
1.58.0
minor
|
1.58.0
minor
Dependencies (36)
+ 28 more |
|
1.57.0
minor
|
1.57.0
minor
Dependencies (36)
+ 28 more |
|
1.56.0
minor
|
1.56.0
minor
Dependencies (37)
+ 29 more |
|
1.55.0
minor
|
1.55.0
minor
Dependencies (37)
+ 29 more |
|
1.54.0
minor
|
1.54.0
minor
Dependencies (37)
+ 29 more |
|
1.53.1
patch
1 CVE
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.53.1
patch
Dependencies (37)
+ 29 more |
|
1.53.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.53.0
minor
Dependencies (37)
+ 29 more |
|
1.52.2
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.52.2
patch
Dependencies (30)
+ 22 more |
|
1.52.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.52.1
patch
Dependencies (30)
+ 22 more |
|
1.52.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.52.0
minor
Dependencies (30)
+ 22 more |
|
1.51.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.51.0
minor
Dependencies (29)
+ 21 more |
|
1.50.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.50.0
minor
Dependencies (29)
+ 21 more |
|
1.49.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.49.1
patch
Dependencies (29)
+ 21 more |
|
1.49.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.49.0
minor
Dependencies (29)
+ 21 more |
|
1.48.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.48.1
patch
Dependencies (28)
+ 20 more |
|
1.48.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.48.0
minor
Dependencies (28)
+ 20 more |
|
1.47.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.47.1
patch
Dependencies (20)
+ 12 more |
|
1.47.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.47.0
minor
Dependencies (20)
+ 12 more |
|
1.46.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.46.1
patch
Dependencies (20)
+ 12 more |
|
1.46.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.46.0
minor
Dependencies (20)
+ 12 more |
|
1.45.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.45.1
patch
Dependencies (20)
+ 12 more |
|
1.45.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.45.0
minor
Dependencies (20)
+ 12 more |
|
1.44.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.44.1
patch
Dependencies (20)
+ 12 more |
|
1.44.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.44.0
minor
Dependencies (20)
+ 12 more |
|
1.43.2
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.43.2
patch
Dependencies (20)
+ 12 more |
|
1.43.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.43.1
patch
Dependencies (20)
+ 12 more |
|
1.43.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.43.0
minor
Dependencies (20)
+ 12 more |
|
1.42.2
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.42.2
patch
Dependencies (21)
+ 13 more |
|
1.42.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.42.1
patch
Dependencies (21)
+ 13 more |
|
1.42.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.42.0
minor
Dependencies (21)
+ 13 more |
|
1.39.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.39.1
patch
Dependencies (21)
+ 13 more |
|
1.41.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.41.1
patch
Dependencies (21)
+ 13 more |
|
1.41.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.41.0
minor
Dependencies (21)
+ 13 more |
|
1.40.2
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.40.2
patch
Dependencies (21)
+ 13 more |
|
1.40.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.40.1
patch
Dependencies (21)
+ 13 more |
|
1.40.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.40.0
minor
Dependencies (21)
+ 13 more |
|
1.39.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.39.0
minor
Dependencies (21)
+ 13 more |
|
1.26.1
patch
4 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-42474
GHSA-rxff-vr5r-8cj5
PYSEC-2024-153
Aug 12, 2024
Path traveral in Streamlit on windows
Medium
Network
Low
Low
None
1. Impacted ProductsStreamilt Open Source versions before 1.37.0. 2. IntroductionSnowflake Streamlit open source addressed a security vulnerability via the static file sharing feature. The vulnerability was patched on Jul 25, 2024, as part of Streamlit open source version 1.37.0. The vulnerability only affects Windows. 3. Path Traversal Vulnerability3.1 DescriptionOn May 12, 2024, Streamlit was informed via our bug bounty program about a path traversal vulnerability in the open source library. We fixed and merged a patch remediating the vulnerability on Jul 25, 2024. The issue was determined to be in the moderate severity range with a maximum CVSSv3 base score of 5.9 3.2 Scenarios and attack vector(s)Users of hosted Streamlit app(s) on Windows were vulnerable to a path traversal vulnerability when the static file sharing feature is enabled. An attacker could utilize the vulnerability to leak the password hash of the Windows user running Streamlit. 3.3 ResolutionThe vulnerability has been fixed in all Streamlit versions released since Jul 25, 2024. We recommend all users upgrade to Version 1.37.0. 4. ContactPlease contact security@snowflake.com if you have any questions regarding this advisory. If you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 212 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.37.0
References
Updated Nov 26, 2024 · Source: OSV.dev
GHSA-8qw9-gf7w-42x5
Jan 12, 2024
Minor fix to previous patch for CVE-2022-35918
5.3
/ 10
Medium
Network
High
None
Required
Unchanged
High
None
None
ImpactThe initial vulnerability identified in Streamlit apps using custom components, allowing for directory traversal attacks, was addressed in version 1.11.1. However, a minor issue persisted, which could still potentially expose certain files on the server file-system under specific conditions. PatchesWe released an update in version 1.30.0 to further tighten security measures. Users are strongly advised to update to version 1.30.0 immediately for optimal security. WorkaroundsNo additional workarounds are necessary once the update to version 1.30.0 is applied. For more informationIf you have any questions or comments about this advisory:
Affected versions
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
+ 100 more Show less
0.69.1
0.69.2
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.4.0
1.5.0
1.5.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.30.0
References
Updated Jun 30, 2026 · Source: OSV.dev |
1.26.1
patch
Dependencies (25)
+ 17 more |
|
1.38.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.38.0
minor
Dependencies (21)
+ 13 more |
|
1.37.1
patch
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.37.1
patch
Dependencies (21)
+ 13 more |
|
1.37.0
minor
2 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev |
1.37.0
minor
Dependencies (21)
+ 13 more |
|
1.36.0
minor
3 CVEs
CVE-2026-10804
GHSA-vqwp-45wm-r9r5
PYSEC-2026-212
Jun 04, 2026
Streamlit @st.cache_data hash collision via fixed sampling seed and PIL P-mode palette omission
Low
Local
High
Low
None
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The pull request to fix this issue awaits acceptance. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 246 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.53.1
References
Updated Jul 15, 2026 · Source: OSV.dev
CVE-2026-33682
PYSEC-2026-2285
GHSA-7p48-42j8-8846
Mar 26, 2026
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code paths, including within the Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 247 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.37.0
1.37.1
1.38.0
1.39.0
1.39.1
1.4.0
1.40.0
1.40.1
1.40.2
1.41.0
1.41.1
1.42.0
1.42.1
1.42.2
1.43.0
1.43.1
1.43.2
1.44.0
1.44.1
1.45.0
1.45.1
1.46.0
1.46.1
1.47.0
1.47.1
1.48.0
1.48.1
1.49.0
1.49.1
1.5.0
1.5.1
1.50.0
1.51.0
1.52.0
1.52.1
1.52.2
1.53.0
1.53.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.54.0
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2024-42474
GHSA-rxff-vr5r-8cj5
PYSEC-2024-153
Aug 12, 2024
Path traveral in Streamlit on windows
Medium
Network
Low
Low
None
1. Impacted ProductsStreamilt Open Source versions before 1.37.0. 2. IntroductionSnowflake Streamlit open source addressed a security vulnerability via the static file sharing feature. The vulnerability was patched on Jul 25, 2024, as part of Streamlit open source version 1.37.0. The vulnerability only affects Windows. 3. Path Traversal Vulnerability3.1 DescriptionOn May 12, 2024, Streamlit was informed via our bug bounty program about a path traversal vulnerability in the open source library. We fixed and merged a patch remediating the vulnerability on Jul 25, 2024. The issue was determined to be in the moderate severity range with a maximum CVSSv3 base score of 5.9 3.2 Scenarios and attack vector(s)Users of hosted Streamlit app(s) on Windows were vulnerable to a path traversal vulnerability when the static file sharing feature is enabled. An attacker could utilize the vulnerability to leak the password hash of the Windows user running Streamlit. 3.3 ResolutionThe vulnerability has been fixed in all Streamlit versions released since Jul 25, 2024. We recommend all users upgrade to Version 1.37.0. 4. ContactPlease contact security@snowflake.com if you have any questions regarding this advisory. If you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our Vulnerability Disclosure Policy. Affected versions
0.1
0.11.0
0.12.2
0.12.3
0.12.4
0.13.0
0.13.1
0.13.3
0.13.5
0.14.2
0.15.0
0.15.1
+ 212 more Show less
0.15.2
0.15.3
0.15.4
0.15.5
0.15.6
0.16.0
0.16.1
0.16.2
0.16.3
0.17.0
0.17.1
0.17.2
0.18.0
0.18.1
0.19.0
0.19.1
0.2
0.20.0
0.21.0
0.22.0
0.22.1
0.22.2
0.23.0
0.24.0
0.24.1
0.24.2
0.24.3
0.25.0
0.26.0
0.26.1
0.27.0
0.28.0
0.29.0
0.3
0.30.0
0.31.0
0.32.0
0.33.0
0.34.0
0.35.0
0.36.0
0.37.0
0.4
0.40.0
0.40.1
0.41.0
0.42.0
0.43.0
0.43.1
0.43.2
0.44.0
0.45.0
0.46.0
0.47.0
0.47.1
0.47.2
0.47.3
0.47.4
0.48.0
0.48.1
0.49.0
0.5
0.50.0
0.50.1
0.50.2
0.51.0
0.52.0
0.52.1
0.52.2
0.53.0
0.54.0
0.55.0
0.55.2
0.56.0
0.57.0
0.57.1
0.57.2
0.57.3
0.58.0
0.59.0
0.6
0.60.0
0.61.0
0.62.0
0.62.1
0.63.0
0.63.1
0.64.0
0.65.0
0.65.1
0.65.2
0.66.0
0.67.0
0.67.1
0.68.0
0.68.1
0.69.0
0.69.1
0.69.2
0.7
0.70.0
0.71.0
0.72.0
0.73.0
0.73.1
0.74.0
0.74.1
0.75.0
0.76.0
0.77.0
0.78.0
0.79.0
0.8
0.8.2
0.80.0
0.81.0
0.81.1
0.82.0
0.83.0
0.84.0
0.84.1
0.84.2
0.85.0
0.85.1
0.86.0
0.87.0
0.88.0
0.89.0
0.9.0
1.0.0
1.1.0
1.10.0
1.10.0rc1
1.10.0rc2
1.11.0
1.11.0rc1
1.11.1
1.11.1rc1
1.12.0
1.12.0rc1
1.12.0rc2
1.12.1
1.12.1rc1
1.12.2
1.12.2rc1
1.12.2rc2
1.13.0
1.13.0rc1
1.13.0rc2
1.14.0
1.14.0rc1
1.14.1
1.14.1rc1
1.15.0
1.15.1
1.15.2
1.15.2rc1
1.16.0
1.17.0
1.18.0
1.18.1
1.18.1rc1
1.19.0
1.2.0
1.20.0
1.21.0
1.22.0
1.23.0
1.23.1
1.24.0
1.24.1
1.25.0
1.26.0
1.26.1
1.27.0
1.27.1
1.27.2
1.28.0
1.28.1
1.28.2
1.29.0
1.3.0
1.3.1
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.2rc1
1.33.0
1.34.0
1.35.0
1.36.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.0rc3
1.6.0rc4
1.7.0
1.8.0
1.8.0rc1
1.8.1
1.8.1rc1
1.9.0
1.9.0rc1
1.9.1
1.9.1rc1
1.9.1rc2
1.9.2
1.9.2rc1
Fixed in
1.37.0
References
Updated Nov 26, 2024 · Source: OSV.dev |
1.36.0
minor
Dependencies (21)
+ 13 more |