Technology · PyPI
OctoPrint (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 24 vulnerabilities in OctoPrint (PyPI): 0 in the last 7 days and 8 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-54134, was published on 21 August 2026.
- Last 7 days
- 0
- Last 90 days
- 8
- Critical, all time
- 0
- Exploited in the wild
- 0
About OctoPrint (PyPI)
An open-source web interface for 3D printers that allows for remote monitoring and control.
Latest OctoPrint (PyPI) vulnerabilities
- CVE-2026-54134: OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom…highCVSS 4EPSS 0.3%
- CVE-2026-35163: OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command…mediumCVSS 4EPSS 0.2%
- CVE-2026-23892: PYSEC-2026-1716 - OctoPrint has Timing Side-Channel Vulnerability in API Key AuthenticationlowCVSS 3.1EPSS 0.4%
- CVE-2025-64187: PYSEC-2026-1714 - OctoPrint vulnerable to XSS in Action Commands Notification and PromptmediumCVSS 4EPSS 0.2%
- CVE-2025-58180: PYSEC-2026-1712 - OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File UploadlowCVSS 3.1EPSS 20.6%
- CVE-2025-48879: PYSEC-2026-1713 - OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrintlowCVSS 3.1EPSS 0.3%
- CVE-2025-48067: PYSEC-2026-1715 - OctoPrint vulnerable to possible file extraction via upload endpointslowCVSS 3.1EPSS 0.3%
- CVE-2022-2822: PYSEC-2026-887 - OctoPrint does not have rate limiting on the login pagelowCVSS 3.1EPSS 0.9%
- CVE-2025-32788: PYSEC-2025-56 - OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including…lowCVSS 3.1EPSS 0.3%
- CVE-2024-51493: PYSEC-2024-202 - OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and…lowCVSS 3.1EPSS 0.3%
- CVE-2024-49377: PYSEC-2024-201 - OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and…lowCVSS 3.1EPSS 0.3%
- CVE-2024-32977: PYSEC-2024-237 - OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and…lowCVSS 3.1EPSS 0.9%
- CVE-2024-28237: PYSEC-2024-179 - OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and…lowCVSS 3.1EPSS 0.4%
- CVE-2024-23637: PYSEC-2024-29 - OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a…lowCVSS 3.1EPSS 0.5%
- CVE-2023-41047: PYSEC-2023-195 - OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a…lowCVSS 3.1EPSS 0.6%
- CVE-2022-3607: PYSEC-2022-42975 - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub…lowCVSS 3EPSS 0.4%
- CVE-2022-2888: PYSEC-2022-282 - If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means…lowCVSS 3.1EPSS 0.3%
- CVE-2022-3068: PYSEC-2022-283 - Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.lowCVSS 3.1EPSS 0.5%
- CVE-2022-2872: PYSEC-2022-286 - Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.lowCVSS 3EPSS 0.7%
- CVE-2022-2930: PYSEC-2022-43142 - Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.lowCVSS 3.1EPSS 0.4%
- CVE-2022-1432: PYSEC-2022-201 - Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0.lowCVSS 3EPSS 1.2%
- CVE-2022-1430: PYSEC-2022-200 - Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.lowCVSS 3EPSS 1.3%
- CVE-2021-32560: PYSEC-2021-29 - The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage…lowCVSS 3.1EPSS 1.5%
- CVE-2021-32561: PYSEC-2021-30 - OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.lowCVSS 3.1EPSS 1.1%
Most severe OctoPrint (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-54134: OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom…highCVSS 4EPSS 0.3%
- CVE-2026-35163: OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command…mediumCVSS 4EPSS 0.2%
- CVE-2025-64187: PYSEC-2026-1714 - OctoPrint vulnerable to XSS in Action Commands Notification and PromptmediumCVSS 4EPSS 0.2%
- CVE-2025-58180: PYSEC-2026-1712 - OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File UploadlowCVSS 3.1EPSS 20.6%
- CVE-2021-32560: PYSEC-2021-29 - The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage…lowCVSS 3.1EPSS 1.5%
- CVE-2021-32561: PYSEC-2021-30 - OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.lowCVSS 3.1EPSS 1.1%
- CVE-2024-32977: PYSEC-2024-237 - OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and…lowCVSS 3.1EPSS 0.9%
- CVE-2022-2822: PYSEC-2026-887 - OctoPrint does not have rate limiting on the login pagelowCVSS 3.1EPSS 0.9%
- CVE-2023-41047: PYSEC-2023-195 - OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a…lowCVSS 3.1EPSS 0.6%
- CVE-2024-23637: PYSEC-2024-29 - OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a…lowCVSS 3.1EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 6 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 2 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/octoprint.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "OctoPrint (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/octoprint, 27 September 2026.