Technology · PyPI
vantage6 (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 23 vulnerabilities in vantage6 (PyPI): 0 in the last 7 days and 8 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-73652, was published on 19 August 2026.
- Last 7 days
- 0
- Last 90 days
- 8
- Critical, all time
- 0
- Exploited in the wild
- 0
About vantage6 (PyPI)
A privacy-preserving federated learning infrastructure for secure data sharing.
Latest vantage6 (PyPI) vulnerabilities
- CVE-2026-73652: PYSEC-2026-3703 - vantage6: Algorithm developer can edit another developer's algorithm that is pending / under reviewmediumCVSS 4EPSS 0.4%
- vantage6 incorrect authorization in algorithm review processhighCVSS 7.1
- CVE-2024-32969: PYSEC-2026-2007 - vantage6 collaboration admins can extend their influence by expanding the collaborationlowCVSS 3.1EPSS 0.3%
- CVE-2024-24770: PYSEC-2026-2005 - vantage6 vulnerable to a username timing attack on recover password/MFA tokenlowCVSS 3.1EPSS 0.4%
- CVE-2024-23823: PYSEC-2026-2004 - vantage6's CORS settings overly permissivelowCVSS 3.1EPSS 0.3%
- CVE-2024-21671: PYSEC-2026-2008 - vantage6 vulnerable to username timing attacklowCVSS 3.1EPSS 0.4%
- CVE-2024-21653: PYSEC-2026-2003 - vantage6 has insecure SSH configuration for node and server containerslowCVSS 3.1EPSS 0.5%
- CVE-2023-28635: PYSEC-2026-2006 - Defining resource name as integer may give unintended access in vantage6lowCVSS 3.1EPSS 0.4%
- CVE-2026-54533: vantage6 improper access control in algorithm containersmediumCVSS 4EPSS 0.5%
- CVE-2026-54445: vantage6 use of default root credentialsmediumCVSS 4EPSS 0.5%
- CVE-2024-27928: vantage6 two-factor authentication bypass via email resetmediumCVSS 4EPSS 0.3%
- CVE-2024-24769: vantage6 uncontrolled resource consumption in MFA reset APImediumCVSS 4EPSS 0.3%
- vantage6 Improper Access Control in node componentmediumCVSS 6.9
- Vantage6 use of default password for root administrator accountmediumCVSS 6.9
- CVE-2025-43863: vantage6 brute-force protection bypass in change password functionalitymediumCVSS 4EPSS 0.5%
- CVE-2024-21649: PYSEC-2024-30 - The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated…lowCVSS 3.1EPSS 1.3%
- CVE-2024-22193: PYSEC-2024-32 - The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated…lowCVSS 3.1EPSS 0.3%
- CVE-2023-41882: PYSEC-2023-201 - vantage6 is privacy preserving federated learning infrastructure. The endpoint…lowCVSS 3.1EPSS 0.4%
- CVE-2023-41881: PYSEC-2023-200 - vantage6 is privacy preserving federated learning infrastructure. When a collaboration is deleted, the…lowCVSS 3.1EPSS 0.3%
- CVE-2023-23930: PYSEC-2023-196 - vantage6 is privacy preserving federated learning infrastructure. Versions prior to 4.0.0 use pickle…lowCVSS 3.1EPSS 0.9%
- CVE-2023-23929: PYSEC-2023-54 - vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently…lowCVSS 3.1EPSS 0.6%
- CVE-2023-22738: PYSEC-2023-53 - vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Assigning…lowCVSS 3.1EPSS 0.4%
- CVE-2022-39228: vantage6 username enumeration via account lockout discrepancymediumCVSS 6.5EPSS 0.6%
Most severe vantage6 (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- vantage6 incorrect authorization in algorithm review processhighCVSS 7.1
- vantage6 Improper Access Control in node componentmediumCVSS 6.9
- Vantage6 use of default password for root administrator accountmediumCVSS 6.9
- CVE-2022-39228: vantage6 username enumeration via account lockout discrepancymediumCVSS 6.5EPSS 0.6%
- CVE-2026-54533: vantage6 improper access control in algorithm containersmediumCVSS 4EPSS 0.5%
- CVE-2026-54445: vantage6 use of default root credentialsmediumCVSS 4EPSS 0.5%
- CVE-2025-43863: vantage6 brute-force protection bypass in change password functionalitymediumCVSS 4EPSS 0.5%
- CVE-2026-73652: PYSEC-2026-3703 - vantage6: Algorithm developer can edit another developer's algorithm that is pending / under reviewmediumCVSS 4EPSS 0.4%
- CVE-2024-27928: vantage6 two-factor authentication bypass via email resetmediumCVSS 4EPSS 0.3%
- CVE-2024-24769: vantage6 uncontrolled resource consumption in MFA reset APImediumCVSS 4EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 6 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 1 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/vantage6.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "vantage6 (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/vantage6, 26 September 2026.