Python / CPython
75 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-6069 | HTMLParser quadratic complexity when processing malformed inputs | MEDIUM | 4.3 | Jun 17, 2025 |
| CVE-2024-12718 | Bypass extraction filter to modify file metadata outside extraction directory | HIGH | 7.6 | Jun 3, 2025 |
| CVE-2025-4435 | Tarfile extracts filtered members when errorlevel=0 | HIGH | 7.5 | Jun 3, 2025 |
| CVE-2025-4138 | Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory | HIGH | 7.5 | Jun 3, 2025 |
| CVE-2025-4330 | Extraction filter bypass for linking outside extraction directory | HIGH | 7.5 | Jun 3, 2025 |
| CVE-2025-4517 | Arbitrary writes via tarfile realpath overflow | CRITICAL | 9.4 | Jun 3, 2025 |
| CVE-2025-4516 | Use-after-free in "unicode_escape" decoder with error handler | MEDIUM | 5.9 | May 15, 2025 |
| CVE-2025-1795 | Mishandling of comma during folding and unicode-encoding of email headers | LOW | 2.3 | Feb 28, 2025 |
| CVE-2024-3220 | Default mimetype known files writeable on Windows | LOW | 2.3 | Feb 14, 2025 |
| CVE-2025-0938 | URL parser allowed square brackets in domain names | MEDIUM | 6.3 | Jan 31, 2025 |
| CVE-2024-12254 | Unbounded memory buffering in SelectorSocketTransport.writelines() | HIGH | 8.7 | Dec 6, 2024 |
| CVE-2024-11168 | Improper validation of IPv6 and IPvFuture addresses | MEDIUM | 6.3 | Nov 12, 2024 |
| CVE-2024-9287 | Virtual environment (venv) activation scripts don't quote paths | MEDIUM | 5.3 | Oct 22, 2024 |
| CVE-2024-6232 | Regular-expression DoS when parsing TarFile headers | HIGH | 7.5 | Sep 3, 2024 |
| CVE-2024-8088 | Infinite loop when iterating over zip archive entry names from zipfile.Path | HIGH | 8.7 | Aug 22, 2024 |
| CVE-2024-7592 | Quadratic complexity parsing cookies with backslashes | HIGH | 7.5 | Aug 19, 2024 |
| CVE-2024-6923 | Email header injection due to unquoted newlines | MEDIUM | 6.8 | Aug 1, 2024 |
| CVE-2024-3219 | Pure-Python fallback of socket.socketpair() doesn’t authenticate peer connection | MEDIUM | 5.1 | Jul 29, 2024 |
| CVE-2024-5642 | Buffer overread when using an empty list with SSLContext.set_npn_protocols() | MEDIUM | 6.5 | Jun 27, 2024 |
| CVE-2024-0397 | Memory race condition in ssl.SSLContext certificate store methods | HIGH | 7.4 | Jun 17, 2024 |
| CVE-2024-4032 | Incorrect IPv4 and IPv6 private ranges | HIGH | 7.5 | Jun 17, 2024 |
| CVE-2024-4030 | tempfile.mkdtemp() may be readable and writeable by all users on Windows | HIGH | 7.1 | May 7, 2024 |
| CVE-2023-6597 | python: Path traversal on tempfile.TemporaryDirectory | HIGH | 7.8 | Mar 19, 2024 |
| CVE-2024-0450 | Quoted zip-bomb protection for zipfile | MEDIUM | 6.2 | Mar 19, 2024 |
| CVE-2023-6507 | Groups not dropped before running subprocess when using empty 'extra_groups' parameter | MEDIUM | 6.1 | Dec 8, 2023 |
Showing 51 to 75 of 75 CVEs