CPython

Python · 75 CVEs

CVE-2026-19553
HIGH

SSLContext.wrap_bio() missing validation of server_hostname parameter

Sep 30, 2026

CVE-2026-19445
CRITICAL

Use-after-free of a server-side SSLContext when sni_callback switches contexts

Sep 30, 2026

CVE-2026-12345
MEDIUM

Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory

Sep 29, 2026

CVE-2026-82049
HIGH

tarfile extraction filters allow file modification and content disclosure via hard link to symlink

Sep 14, 2026

CVE-2026-87910
MEDIUM

tarfile hardlink fallback ignores custom extraction filter rejection via None

Sep 11, 2026

CVE-2026-15310
LOW

zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

Aug 25, 2026

CVE-2026-19672
MEDIUM

tarfile extraction filter bypass allows creation of directories outside the destination

Aug 19, 2026

CVE-2026-15806
MEDIUM

`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching

Aug 18, 2026

CVE-2026-17084
MEDIUM

stringprep.map_table_b2() deviates from RFC 3454 Table B.2

Aug 18, 2026

CVE-2026-18503
LOW

Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()

Aug 10, 2026

CVE-2026-6879
LOW

Quadratic Behavior in xml.etree.ElementPath Index Predicates

Jul 28, 2026

CVE-2026-15308
HIGH

Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations

Jul 9, 2026

CVE-2026-4360
LOW

Tarfile.extract() doesn't fully respect filter parameter

Jun 30, 2026

CVE-2026-11972
HIGH

tarfile opened in streaming mode mishandles EOF

Jun 23, 2026

CVE-2026-0864
MEDIUM

Configuration Injection via Carriage Return (\r) in write() method

Jun 23, 2026

CVE-2026-11940
HIGH

tarfile extraction filter bypass allows escaping the destination directory

Jun 23, 2026

CVE-2026-12003
MEDIUM

CPython >3.11 Insecure Input Validation resulting in privilege escalation

Jun 16, 2026

CVE-2026-9669
HIGH

bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow

Jun 8, 2026

CVE-2026-7774
MEDIUM

tarfile.data_filter path traversal bypass allows writing outside the extraction directory

Jun 4, 2026

CVE-2026-3276
MEDIUM

Potential DoS via quadratic complexity in unicodedata.normalize()

Jun 3, 2026

CVE-2026-8328
MEDIUM

FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address

May 13, 2026

CVE-2026-7210
MEDIUM

The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

May 11, 2026

CVE-2026-3087
MEDIUM

shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

Apr 27, 2026

CVE-2026-6019
LOW

BaseCookie.js_output() does not neutralize embedded characters

Apr 22, 2026

CVE-2026-3298
HIGH

Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes

Apr 21, 2026

Showing 1 to 25 of 75 CVEs