Python / CPython
75 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-19553 | SSLContext.wrap_bio() missing validation of server_hostname parameter | HIGH | 7.6 | Sep 30, 2026 |
| CVE-2026-19445 | Use-after-free of a server-side SSLContext when sni_callback switches contexts | CRITICAL | 9.2 | Sep 30, 2026 |
| CVE-2026-12345 | Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory | MEDIUM | 5.9 | Sep 29, 2026 |
| CVE-2026-82049 | tarfile extraction filters allow file modification and content disclosure via hard link to symlink | HIGH | 8.4 | Sep 14, 2026 |
| CVE-2026-87910 | tarfile hardlink fallback ignores custom extraction filter rejection via None | MEDIUM | 5.7 | Sep 11, 2026 |
| CVE-2026-15310 | zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits | LOW | 2.1 | Aug 25, 2026 |
| CVE-2026-19672 | tarfile extraction filter bypass allows creation of directories outside the destination | MEDIUM | 6.3 | Aug 19, 2026 |
| CVE-2026-15806 | `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching | MEDIUM | 6.0 | Aug 18, 2026 |
| CVE-2026-17084 | stringprep.map_table_b2() deviates from RFC 3454 Table B.2 | MEDIUM | 6.0 | Aug 18, 2026 |
| CVE-2026-18503 | Super-linear CPU usage for unbounded input to csv.Sniffer.sniff() | LOW | 2.4 | Aug 10, 2026 |
| CVE-2026-6879 | Quadratic Behavior in xml.etree.ElementPath Index Predicates | LOW | 2.0 | Jul 28, 2026 |
| CVE-2026-15308 | Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations | HIGH | 8.7 | Jul 9, 2026 |
| CVE-2026-4360 | Tarfile.extract() doesn't fully respect filter parameter | LOW | 2.0 | Jun 30, 2026 |
| CVE-2026-11972 | tarfile opened in streaming mode mishandles EOF | HIGH | 8.2 | Jun 23, 2026 |
| CVE-2026-0864 | Configuration Injection via Carriage Return (\r) in write() method | MEDIUM | 4.1 | Jun 23, 2026 |
| CVE-2026-11940 | tarfile extraction filter bypass allows escaping the destination directory | HIGH | 7.8 | Jun 23, 2026 |
| CVE-2026-12003 | CPython >3.11 Insecure Input Validation resulting in privilege escalation | MEDIUM | 5.3 | Jun 16, 2026 |
| CVE-2026-9669 | bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow | HIGH | 8.2 | Jun 8, 2026 |
| CVE-2026-7774 | tarfile.data_filter path traversal bypass allows writing outside the extraction directory | MEDIUM | 6.9 | Jun 4, 2026 |
| CVE-2026-3276 | Potential DoS via quadratic complexity in unicodedata.normalize() | MEDIUM | 6.3 | Jun 3, 2026 |
| CVE-2026-8328 | FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address | MEDIUM | 5.9 | May 13, 2026 |
| CVE-2026-7210 | The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection | MEDIUM | 6.3 | May 11, 2026 |
| CVE-2026-3087 | shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs | MEDIUM | 6.0 | Apr 27, 2026 |
| CVE-2026-6019 | BaseCookie.js_output() does not neutralize embedded characters | LOW | 2.1 | Apr 22, 2026 |
| CVE-2026-3298 | Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes | HIGH | 8.8 | Apr 21, 2026 |
Showing 1 to 25 of 75 CVEs