Technology · PyPI
ethyca-fides (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 21 vulnerabilities in ethyca-fides (PyPI): 0 in the last 7 days and 18 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-57817, was published on 7 July 2026.
- Last 7 days
- 0
- Last 90 days
- 18
- Critical, all time
- 0
- Exploited in the wild
- 0
About ethyca-fides (PyPI)
An open-source privacy engineering platform for managing data privacy requests and compliance.
Latest ethyca-fides (PyPI) vulnerabilities
- CVE-2025-57817: PYSEC-2026-1343 - Fides Webserver API is Vulnerable to OAuth Client Privilege EscalationlowCVSS 3.1EPSS 0.4%
- CVE-2025-57816: PYSEC-2026-1341 - Fides Webserver API Rate Limiting Vulnerability in Proxied EnvironmentslowCVSS 3.1EPSS 0.4%
- CVE-2025-57815: PYSEC-2026-1335 - Fides has a Lack of Brute-Force Protections on Authentication EndpointslowCVSS 3.1EPSS 0.3%
- CVE-2025-57766: PYSEC-2026-1348 - Fides' Admin UI User Password Change Does Not Invalidate Current SessionlowCVSS 3.1EPSS 0.3%
- CVE-2024-52008: PYSEC-2026-1349 - Password Policy Bypass Vulnerability in Fides Webserver User Accept Invite APIlowCVSS 3.1EPSS 0.6%
- CVE-2024-45052: PYSEC-2026-1331 - Timing-Based Username Enumeration Vulnerability in Fides Webserver AuthenticationinfoEPSS 0.6%
- CVE-2024-31223: PYSEC-2026-1334 - Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URLlowCVSS 3.1EPSS 1.1%
- CVE-2024-38537: PYSEC-2026-1339 - Inclusion of Untrusted polyfill.io Code Vulnerability in fides.jslowCVSS 3.1EPSS 1.4%
- CVE-2024-35189: PYSEC-2026-1346 - Sensitive Data Disclosure Vulnerability in Connection Configuration EndpointslowCVSS 3.1EPSS 0.6%
- CVE-2024-34715: PYSEC-2026-1337 - Fides Webserver Logs Hosted Database Password Partial Exposure VulnerabilitylowCVSS 3.1EPSS 0.3%
- CVE-2023-48224: PYSEC-2026-1336 - Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity VerificationlowCVSS 3.1EPSS 1.0%
- CVE-2023-47114: PYSEC-2026-1333 - Ethyca Fides HTML Injection Vulnerability in HTML-Formatted DSR PackageslowCVSS 3.1EPSS 0.6%
- CVE-2023-46126: PYSEC-2026-1340 - Fides JavaScript Injection Vulnerability in Privacy Center URLlowCVSS 3.1EPSS 0.6%
- CVE-2023-46125: PYSEC-2026-1347 - Fides Information Disclosure Vulnerability in Config API EndpointlowCVSS 3.1EPSS 0.7%
- CVE-2023-46124: PYSEC-2026-1344 - Fides Server-Side Request Forgery Vulnerability in Custom Integration UploadlowCVSS 3.1EPSS 0.7%
- CVE-2023-41319: PYSEC-2026-1345 - Remote Code Execution in Custom Integration UploadlowCVSS 3.1EPSS 0.9%
- CVE-2023-37481: PYSEC-2026-1332 - Fides Webserver Vulnerable to SVG Bomb File UploadslowCVSS 3.1EPSS 0.7%
- CVE-2023-37480: PYSEC-2026-1342 - Fides Webserver Vulnerable to Zip Bomb File UploadslowCVSS 3.1EPSS 0.7%
- CVE-2026-44541: Ethyca Fides DOM-based XSS in fides.js via description overridehighCVSS 4EPSS 0.5%
- CVE-2026-42303: Ethyca Fides authentication bypass in privacy request approvalmediumCVSS 4EPSS 0.5%
- CVE-2023-36827: PYSEC-2023-107 - Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy…lowCVSS 3.1EPSS 1.5%
Most severe ethyca-fides (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-44541: Ethyca Fides DOM-based XSS in fides.js via description overridehighCVSS 4EPSS 0.5%
- CVE-2026-42303: Ethyca Fides authentication bypass in privacy request approvalmediumCVSS 4EPSS 0.5%
- CVE-2023-36827: PYSEC-2023-107 - Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy…lowCVSS 3.1EPSS 1.5%
- CVE-2024-38537: PYSEC-2026-1339 - Inclusion of Untrusted polyfill.io Code Vulnerability in fides.jslowCVSS 3.1EPSS 1.4%
- CVE-2024-31223: PYSEC-2026-1334 - Information Disclosure Vulnerability in Privacy Center of SERVER_SIDE_FIDES_API_URLlowCVSS 3.1EPSS 1.1%
- CVE-2023-48224: PYSEC-2026-1336 - Ethyca Fides Cryptographically Weak Generation of One-Time Codes for Identity VerificationlowCVSS 3.1EPSS 1.0%
- CVE-2023-41319: PYSEC-2026-1345 - Remote Code Execution in Custom Integration UploadlowCVSS 3.1EPSS 0.9%
- CVE-2023-46125: PYSEC-2026-1347 - Fides Information Disclosure Vulnerability in Config API EndpointlowCVSS 3.1EPSS 0.7%
- CVE-2023-37481: PYSEC-2026-1332 - Fides Webserver Vulnerable to SVG Bomb File UploadslowCVSS 3.1EPSS 0.7%
- CVE-2023-37480: PYSEC-2026-1342 - Fides Webserver Vulnerable to Zip Bomb File UploadslowCVSS 3.1EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 18 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/ethyca-fides.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "ethyca-fides (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/ethyca-fides, 27 September 2026.