CPython
Python · 75 CVEs
SSLContext.wrap_bio() missing validation of server_hostname parameter
Sep 30, 2026
Use-after-free of a server-side SSLContext when sni_callback switches contexts
Sep 30, 2026
Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory
Sep 29, 2026
tarfile extraction filters allow file modification and content disclosure via hard link to symlink
Sep 14, 2026
tarfile hardlink fallback ignores custom extraction filter rejection via None
Sep 11, 2026
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
Aug 25, 2026
tarfile extraction filter bypass allows creation of directories outside the destination
Aug 19, 2026
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching
Aug 18, 2026
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
Aug 18, 2026
Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()
Aug 10, 2026
Quadratic Behavior in xml.etree.ElementPath Index Predicates
Jul 28, 2026
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Jul 9, 2026
Tarfile.extract() doesn't fully respect filter parameter
Jun 30, 2026
tarfile opened in streaming mode mishandles EOF
Jun 23, 2026
Configuration Injection via Carriage Return (\r) in write() method
Jun 23, 2026
tarfile extraction filter bypass allows escaping the destination directory
Jun 23, 2026
CPython >3.11 Insecure Input Validation resulting in privilege escalation
Jun 16, 2026
bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
Jun 8, 2026
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
Jun 4, 2026
Potential DoS via quadratic complexity in unicodedata.normalize()
Jun 3, 2026
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
May 13, 2026
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
May 11, 2026
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
Apr 27, 2026
BaseCookie.js_output() does not neutralize embedded characters
Apr 22, 2026
Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
Apr 21, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-19553 | SSLContext.wrap_bio() missing validation of server_hostname parameter | HIGH | 0.40% | Sep 30, 2026 |
| CVE-2026-19445 | Use-after-free of a server-side SSLContext when sni_callback switches contexts | CRITICAL | 0.43% | Sep 30, 2026 |
| CVE-2026-12345 | Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory | MEDIUM | 0.18% | Sep 29, 2026 |
| CVE-2026-82049 | tarfile extraction filters allow file modification and content disclosure via hard link to symlink | HIGH | 0.21% | Sep 14, 2026 |
| CVE-2026-87910 | tarfile hardlink fallback ignores custom extraction filter rejection via None | MEDIUM | 0.64% | Sep 11, 2026 |
| CVE-2026-15310 | zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits | LOW | 0.53% | Aug 25, 2026 |
| CVE-2026-19672 | tarfile extraction filter bypass allows creation of directories outside the destination | MEDIUM | 0.52% | Aug 19, 2026 |
| CVE-2026-15806 | `HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching | MEDIUM | 0.46% | Aug 18, 2026 |
| CVE-2026-17084 | stringprep.map_table_b2() deviates from RFC 3454 Table B.2 | MEDIUM | 0.72% | Aug 18, 2026 |
| CVE-2026-18503 | Super-linear CPU usage for unbounded input to csv.Sniffer.sniff() | LOW | 0.12% | Aug 10, 2026 |
| CVE-2026-6879 | Quadratic Behavior in xml.etree.ElementPath Index Predicates | LOW | 0.37% | Jul 28, 2026 |
| CVE-2026-15308 | Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations | HIGH | 0.64% | Jul 9, 2026 |
| CVE-2026-4360 | Tarfile.extract() doesn't fully respect filter parameter | LOW | 0.48% | Jun 30, 2026 |
| CVE-2026-11972 | tarfile opened in streaming mode mishandles EOF | HIGH | 0.71% | Jun 23, 2026 |
| CVE-2026-0864 | Configuration Injection via Carriage Return (\r) in write() method | MEDIUM | 0.13% | Jun 23, 2026 |
| CVE-2026-11940 | tarfile extraction filter bypass allows escaping the destination directory | HIGH | 0.75% | Jun 23, 2026 |
| CVE-2026-12003 | CPython >3.11 Insecure Input Validation resulting in privilege escalation | MEDIUM | 0.15% | Jun 16, 2026 |
| CVE-2026-9669 | bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow | HIGH | 0.60% | Jun 8, 2026 |
| CVE-2026-7774 | tarfile.data_filter path traversal bypass allows writing outside the extraction directory | MEDIUM | 0.78% | Jun 4, 2026 |
| CVE-2026-3276 | Potential DoS via quadratic complexity in unicodedata.normalize() | MEDIUM | 0.71% | Jun 3, 2026 |
| CVE-2026-8328 | FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address | MEDIUM | 0.68% | May 13, 2026 |
| CVE-2026-7210 | The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection | MEDIUM | 1.35% | May 11, 2026 |
| CVE-2026-3087 | shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs | MEDIUM | 0.73% | Apr 27, 2026 |
| CVE-2026-6019 | BaseCookie.js_output() does not neutralize embedded characters | LOW | 0.58% | Apr 22, 2026 |
| CVE-2026-3298 | Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes | HIGH | 0.60% | Apr 21, 2026 |
Showing 1 to 25 of 75 CVEs