IndexedVerified

Python Security

Python SAST rules aggregated across verified providers.

Fetch pack

greprules pack fetch python-security --engine opengrep
curl https://api.greprules.io/api/packs/python-security.tar.gz -o python-security.tar.gz

Included rules

602 rules included. Showing 24 loaded rules.
CVE-2026-56304: Picklescan Incomplete Blocklistcve-2026-56304-picklescan-incomplete-blocklistCVE-2026-56104: Insecure Session Restore By Idcve-2026-56104-insecure-session-restore-by-idCVE-2026-54317: Missing Strict Filename Validationcve-2026-54317-missing-strict-filename-validationCVE-2026-54293: Weak Path Traversal Guard Splitcve-2026-54293-weak-path-traversal-guard-splitCVE-2026-54276: Aiohttp Digest Auth Cross Origin Leakcve-2026-54276-aiohttp-digest-auth-cross-origin-leakCVE-2026-54273: Aiohttp Unbounded Pipelined Request Queuecve-2026-54273-aiohttp-unbounded-pipelined-request-queueCVE-2026-54233: Python Audio Decompression Bombcve-2026-54233-python-audio-decompression-bombCVE-2026-53874: Insecure Pickle Scanner Blocklistcve-2026-53874-insecure-pickle-scanner-blocklistCVE-2026-53873: Picklescan Incomplete Profile Blocklistcve-2026-53873-picklescan-incomplete-profile-blocklistCVE-2026-53872: Incomplete Pickle Deserialization Blocklistcve-2026-53872-incomplete-pickle-deserialization-blocklistCVE-2026-53568: Frappe Unvalidated Query Dict Keycve-2026-53568-frappe-unvalidated-query-dict-keyCVE-2026-52726: Shell Command Replace Injectioncve-2026-52726-shell-command-replace-injectionCVE-2026-50019: Print Sensitive File Contentcve-2026-50019-print-sensitive-file-contentCVE-2026-49959: Unanchored Deletion Toctoucve-2026-49959-unanchored-deletion-toctouCVE-2026-49958: Toctou Dynamic Path Deletioncve-2026-49958-toctou-dynamic-path-deletionCVE-2026-49853: Python Tornado Http Splitting Xsscve-2026-49853-python-tornado-http-splitting-xssCVE-2026-48983: Pamusb Python Command Injectioncve-2026-48983-pamusb-python-command-injectionCVE-2026-48981: Python Os System Command Injectioncve-2026-48981-python-os-system-command-injectionCVE-2026-48746: Starlette Url Path Auth Bypasscve-2026-48746-starlette-url-path-auth-bypassCVE-2026-48681: Python Insecure File Url Path Validationcve-2026-48681-python-insecure-file-url-path-validationCVE-2026-48544: Python Dynamic Method Json Loads Oomcve-2026-48544-python-dynamic-method-json-loads-oomCVE-2026-48155: Python Unbounded Whitespace Multiplicationcve-2026-48155-python-unbounded-whitespace-multiplicationCVE-2026-48065: Python Shell Command Injectioncve-2026-48065-python-shell-command-injectionCVE-2026-48064: Python Shell Command Injectioncve-2026-48064-python-shell-command-injection
24 of 602 loaded