Python / Python
142 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-15308 | Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations | HIGH | 8.7 | Jul 9, 2026 |
| CVE-2026-4360 | Tarfile.extract() doesn't fully respect filter parameter | LOW | 2.0 | Jun 30, 2026 |
| CVE-2026-0864 | Configuration Injection via Carriage Return (\r) in write() method | MEDIUM | 4.1 | Jun 23, 2026 |
| CVE-2026-7210 | The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection | MEDIUM | 6.3 | May 11, 2026 |
| CVE-2026-3087 | shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs | MEDIUM | 6.0 | Apr 27, 2026 |
| CVE-2026-6019 | BaseCookie.js_output() does not neutralize embedded characters | LOW | 2.1 | Apr 22, 2026 |
| CVE-2026-4519 | webbrowser.open() allows leading dashes in URLs | HIGH | 7.0 | Mar 20, 2026 |
| CVE-2026-4224 | Stack overflow parsing XML with deeply nested DTD content models | MEDIUM | 6.0 | Mar 16, 2026 |
| CVE-2026-3644 | Incomplete control character validation in http.cookies | MEDIUM | 6.0 | Mar 16, 2026 |
| CVE-2025-13462 | tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling | LOW | 2.0 | Mar 12, 2026 |
| CVE-2025-12781 | base64.b64decode() always accepts "+/" characters, despite setting altchars | MEDIUM | 6.3 | Jan 21, 2026 |
| CVE-2025-12084 | Quadratic complexity in node ID cache clearing | MEDIUM | 6.3 | Dec 3, 2025 |
| CVE-2025-13837 | Out-of-memory when loading Plist | LOW | 2.1 | Dec 1, 2025 |
| CVE-2025-13836 | Excessive read buffering DoS in http.client | MEDIUM | 6.3 | Dec 1, 2025 |
| CVE-2025-6075 | Quadratic complexity in os.path.expandvars() with user-controlled template | LOW | 1.8 | Oct 31, 2025 |
| CVE-2024-9287 | Virtual environment (venv) activation scripts don't quote paths | MEDIUM | 5.3 | Oct 22, 2024 |
| CVE-2024-6232 | Regular-expression DoS when parsing TarFile headers | HIGH | 7.5 | Sep 3, 2024 |
| CVE-2024-7592 | Quadratic complexity parsing cookies with backslashes | HIGH | 7.5 | Aug 19, 2024 |
| CVE-2023-6507 | Groups not dropped before running subprocess when using empty 'extra_groups' parameter | MEDIUM | 6.1 | Dec 8, 2023 |
| CVE-2023-40217 | python: TLS handshake bypass | HIGH | 8.6 | Aug 25, 2023 |
| CVE-2023-41105 | python: file path truncation at \0 characters | HIGH | 7.5 | Aug 23, 2023 |
| CVE-2022-48566 | python: constant-time-defeating optimisations issue in the compare_digest function in Lib/hmac.p | MEDIUM | 5.9 | Aug 22, 2023 |
| CVE-2022-48565 | python: XML External Entity in XML processing plistlib module | CRITICAL | 9.8 | Aug 22, 2023 |
| CVE-2022-48564 | python: DoS when processing malformed Apple Property List files in binary format | MEDIUM | 6.5 | Aug 22, 2023 |
| CVE-2022-48560 | python: use after free in heappushpop() of heapq module | HIGH | 7.5 | Aug 22, 2023 |
Showing 1 to 25 of 142 CVEs