CVEs we hold for Python
Records whose assigning authority named Python as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9669bz2.BZ2Decompressor reuse after error can cause a stack buffer overflowPython Software Foundation CPython
CVE-2026-87910tarfile hardlink fallback ignores custom extraction filter rejection via NonePython Software Foundation CPython
CVE-2026-8643pip can extract console_scripts and gui_scripts outside installation directoryPython Packaging Authority pip
CVE-2026-8328FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host addressPython Software Foundation CPython
CVE-2026-82049tarfile extraction filters allow file modification and content disclosure via hard link to symlinkPython Software Foundation CPython
CVE-2026-7774tarfile.data_filter path traversal bypass allows writing outside the extraction directoryPython Software Foundation CPython
CVE-2026-7210The expat and elementtree parsers use insufficient entropy for XML hash-flooding protectionPython Software Foundation CPython
CVE-2026-6879Quadratic Behavior in xml.etree.ElementPath Index PredicatesPython Software Foundation CPython
CVE-2026-6100Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressurePython Software Foundation CPython
CVE-2026-6019BaseCookie.js_output() does not neutralize embedded charactersPython Software Foundation CPython
CVE-2026-59205Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatchpython-pillow Pillow
CVE-2026-59204Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of servicepython-pillow Pillow
CVE-2026-59203Pillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of servicepython-pillow Pillow
CVE-2026-59199Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflowpython-pillow Pillow
CVE-2026-59198Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated imagespython-pillow Pillow
CVE-2026-59197Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`python-pillow Pillow
CVE-2026-5713Out-of-bounds read/write during remote profiling and asyncio process introspection when connecting to malicious targetPython Software Foundation CPython
CVE-2026-55798Pillow: WindowsViewer.get_command() OS command injection via unescaped shell pathpython-pillow Pillow
CVE-2026-55379Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font…python-pillow Pillow
CVE-2026-54060Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`python-pillow Pillow
CVE-2026-54059Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb…python-pillow Pillow
CVE-2026-54058Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)python-pillow Pillow
CVE-2026-5271Possible to hijack modules in current working directoryPython Software Foundation pymanager
CVE-2026-48487Zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packetpython-zeroconf
CVE-2026-48045Zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source floodpython-zeroconf
CVE-2026-4786Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()Python Software Foundation CPython
CVE-2026-47184Zeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via multicast floodpython-zeroconf
CVE-2026-47183Zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory…python-zeroconf
CVE-2026-47180Zeroconf: Unbounded recursion in DNS compression-pointer decoder allows LAN-local denial of servicepython-zeroconf
CVE-2026-4360Tarfile.extract() doesn't fully respect filter parameterPython Software Foundation CPython
CVE-2026-42311Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow)python-pillow Pillow
CVE-2026-4224Stack overflow parsing XML with deeply nested DTD content modelsPython Software Foundation CPython
CVE-2026-41140Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4python-poetry poetry
CVE-2026-3644Incomplete control character validation in http.cookiesPython Software Foundation CPython
CVE-2026-3479pkgutil.get_data() does not enforce documented restrictionsPython Software Foundation CPython
CVE-2026-34591Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Writepython-poetry poetry
CVE-2026-3446Base64 decoding stops at first padded quad by defaultPython Software Foundation CPython
CVE-2026-3298Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytesPython Software Foundation CPython
CVE-2026-3276Potential DoS via quadratic complexity in unicodedata.normalize()Python Software Foundation CPython
CVE-2026-3087shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPsPython Software Foundation CPython
CVE-2026-19672tarfile extraction filter bypass allows creation of directories outside the destinationPython Software Foundation CPython
CVE-2026-18503Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()Python Software Foundation CPython
CVE-2026-17084stringprep.map_table_b2() deviates from RFC 3454 Table B.2Python Software Foundation CPython
CVE-2026-15806`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matchingPython Software Foundation CPython
CVE-2026-15310zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limitsPython Software Foundation CPython
CVE-2026-15308Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarationsPython Software Foundation CPython
CVE-2026-1502HTTP client proxy tunnel headers not validated for CR/LFPython Software Foundation CPython
CVE-2026-13346pip absolute path traversal during download from malicious package indexesPython Packaging Authority pip
CVE-2026-1299email BytesGenerator header injection due to unquoted newlinesPython Software Foundation CPython
CVE-2026-12003CPython >3.11 Insecure Input Validation resulting in privilege escalationPython Software Foundation CPython
CVE-2026-11940tarfile extraction filter bypass allows escaping the destination directoryPython Software Foundation CPython
CVE-2026-0865wsgiref.headers.Headers allows header newline injectionPython Software Foundation CPython
CVE-2026-0864Configuration Injection via Carriage Return (\r) in write() methodPython Software Foundation CPython
CVE-2025-8869Fallback tar extraction in pip doesn't check symbolic links point to extraction directoryPython Packaging Authority pip
CVE-2025-8291ZIP64 End of Central Directory (EOCD) Locator record offset not checkedPython Software Foundation CPython
CVE-2025-8194Tarfile infinite loop during parsing with negative member offsetPython Software Foundation CPython
CVE-2025-61912python-ldap Vulnerable to Improper Encoding or Escaping of Output and Improper Null Terminationpython-ldap
CVE-2025-61783Python Social Auth - Django has unsafe account associationpython-social-auth social-app-django
CVE-2025-6075Quadratic complexity in os.path.expandvars() with user-controlled templatePython Software Foundation CPython
CVE-2025-6069HTMLParser quadratic complexity when processing malformed inputsPython Software Foundation CPython
CVE-2025-4516Use-after-free in "unicode_escape" decoder with error handlerPython Software Foundation CPython
CVE-2025-4330Extraction filter bypass for linking outside extraction directoryPython Software Foundation CPython
CVE-2025-4138Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directoryPython Software Foundation CPython
CVE-2025-1795Mishandling of comma during folding and unicode-encoding of email headersPython Software Foundation CPython
CVE-2025-13462tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handlingPython Software Foundation CPython
CVE-2025-12781base64.b64decode() always accepts "+/" characters, despite setting altcharsPython Software Foundation CPython
CVE-2025-11468Folding email comments of unfoldable characters doesn't preserve parenthesisPython Software Foundation CPython
CVE-2024-9287Virtual environment (venv) activation scripts don't quote pathsPython Software Foundation CPython
CVE-2024-8088Infinite loop when iterating over zip archive entry names from zipfile.PathPython Software Foundation CPython
CVE-2024-7592Quadratic complexity parsing cookies with backslashesPython Software Foundation CPython
CVE-2024-5642Buffer overread when using an empty list with SSLContext.set_npn_protocols()Python Software Foundation CPython
CVE-2024-53848check-jsonschema default caching for remote schemas allows for cache confusionpython-jsonschema check-jsonschema
CVE-2024-4030tempfile.mkdtemp() may be readable and writeable by all users on WindowsPython Software Foundation CPython
CVE-2024-32879social-auth-app-django Improper Handling of Case Sensitivity vulnerabilitypython-social-auth social-app-django
CVE-2024-3219Pure-Python fallback of socket.socketpair() doesn’t authenticate peer connectionPython Software Foundation CPython
CVE-2024-12718Bypass extraction filter to modify file metadata outside extraction directoryPython Software Foundation CPython
CVE-2024-12254Unbounded memory buffering in SelectorSocketTransport.writelines()Python Software Foundation CPython
CVE-2024-0397Memory race condition in ssl.SSLContext certificate store methodsPython Software Foundation CPython
CVE-2023-6507Groups not dropped before running subprocess when using empty 'extra_groups' parameterPython Software Foundation CPython
CVE-2022-36070Poetry's Untrusted Search Path can lead to Local Code Execution on Windowspython-poetry poetry
CVE-2022-36069Poetry Argument Injection vulnerability can lead to local Code Executionpython-poetry poetry
142 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.