Python / CPython
75 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-5713 | Out-of-bounds read/write during remote profiling and asyncio process introspection when connecting to malicious target | MEDIUM | 5.3 | Apr 14, 2026 |
| CVE-2026-4786 | Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open() | HIGH | 7.0 | Apr 13, 2026 |
| CVE-2026-6100 | Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure | CRITICAL | 9.1 | Apr 13, 2026 |
| CVE-2026-3446 | Base64 decoding stops at first padded quad by default | MEDIUM | 6.0 | Apr 10, 2026 |
| CVE-2026-1502 | HTTP client proxy tunnel headers not validated for CR/LF | MEDIUM | 5.7 | Apr 10, 2026 |
| CVE-2026-4519 | webbrowser.open() allows leading dashes in URLs | HIGH | 7.0 | Mar 20, 2026 |
| CVE-2026-3479 | pkgutil.get_data() does not enforce documented restrictions | LOW | 3.3 | Mar 18, 2026 |
| CVE-2026-4224 | Stack overflow parsing XML with deeply nested DTD content models | MEDIUM | 6.0 | Mar 16, 2026 |
| CVE-2026-3644 | Incomplete control character validation in http.cookies | MEDIUM | 6.0 | Mar 16, 2026 |
| CVE-2025-13462 | tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling | LOW | 2.0 | Mar 12, 2026 |
| CVE-2026-2297 | SourcelessFileLoader does not use io.open_code() | MEDIUM | 5.7 | Mar 4, 2026 |
| CVE-2026-1299 | email BytesGenerator header injection due to unquoted newlines | MEDIUM | 6.0 | Jan 23, 2026 |
| CVE-2025-12781 | base64.b64decode() always accepts "+/" characters, despite setting altchars | MEDIUM | 6.3 | Jan 21, 2026 |
| CVE-2026-0672 | Header injection in http.cookies.Morsel | MEDIUM | 6.0 | Jan 20, 2026 |
| CVE-2025-15367 | POP3 command injection in user-controlled commands | MEDIUM | 5.9 | Jan 20, 2026 |
| CVE-2025-15366 | IMAP command injection in user-controlled commands | MEDIUM | 5.9 | Jan 20, 2026 |
| CVE-2025-15282 | Header injection via newlines in data URL mediatype | MEDIUM | 6.0 | Jan 20, 2026 |
| CVE-2026-0865 | wsgiref.headers.Headers allows header newline injection | MEDIUM | 5.9 | Jan 20, 2026 |
| CVE-2025-11468 | Folding email comments of unfoldable characters doesn't preserve parenthesis | MEDIUM | 5.7 | Jan 20, 2026 |
| CVE-2025-12084 | Quadratic complexity in node ID cache clearing | MEDIUM | 6.3 | Dec 3, 2025 |
| CVE-2025-13837 | Out-of-memory when loading Plist | LOW | 2.1 | Dec 1, 2025 |
| CVE-2025-13836 | Excessive read buffering DoS in http.client | MEDIUM | 6.3 | Dec 1, 2025 |
| CVE-2025-6075 | Quadratic complexity in os.path.expandvars() with user-controlled template | LOW | 1.8 | Oct 31, 2025 |
| CVE-2025-8291 | ZIP64 End of Central Directory (EOCD) Locator record offset not checked | MEDIUM | 4.3 | Oct 7, 2025 |
| CVE-2025-8194 | Tarfile infinite loop during parsing with negative member offset | HIGH | 7.5 | Jul 28, 2025 |
Showing 26 to 50 of 75 CVEs