Where
-Infinity
0

Python html.parser.HTMLParserIncremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations

Risk 50
Severity
8.7
First published (updated )

python/tarfileTarfile.extract() doesn't fully respect filter parameter

Risk 27
Severity
2
First published (updated )

Python Software Foundation CPythonThe expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

Risk 32
Severity
6.3
EPSS
0.06%
First published (updated )

Python Pythonshutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

Risk 46
Severity
6
First published (updated )

pypi/poetryPath Traversal

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Python http.cookies.MorselBaseCookie.js_output() does not neutralize embedded characters

Risk 27
Severity
2.1
EPSS
0.06%
First published (updated )

Python Pythonwebbrowser.open() allows leading dashes in URLs

Risk 46
Severity
7
EPSS
0.03%
First published (updated )

Python PythonStack overflow parsing XML with deeply nested DTD content models

Risk 32
Severity
6
EPSS
0.03%
First published (updated )

Python PythonIncomplete control character validation in http.cookies

Risk 32
Severity
6
EPSS
0.11%
First published (updated )

Python Pythontarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling

Risk 18
Severity
2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Python Pythonbase64.b64decode() always accepts "+/" characters, despite setting altchars

Risk 29
Severity
6.3
First published (updated )

Forcepoint One DLP ClientVulnerable Python version used in Forcepoint One DLP Client

Risk 69
Severity
7.8
First published (updated )

Python PythonQuadratic complexity in node ID cache clearing

Risk 31
Severity
6.3
First published (updated )

Python PythonOut-of-memory when loading Plist

Risk 34
Severity
2.1
First published (updated )

Python PythonExcessive read buffering DoS in http.client

Risk 46
Severity
6.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Python PythonIf the value passed to os.path.expandvars() is user-controlled a performance degradation is possibl…

Risk 5
Severity
1
First published (updated )

Python PythonQuadratic complexity in os.path.expandvars() with user-controlled template

Risk 32
Severity
1.8
First published (updated )

pip/kerasKeras keras.utils.get_file Utility Path Traversal Vulnerability

Risk 86
Severity
9.8
First published (updated )

Python PythonStarting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "paus…

Risk 32
Severity
7
First published (updated )

debian/python3.11Unbounded memory buffering in SelectorSocketTransport.writelines()

Risk 50
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Python PythonVirtual environment (venv) activation scripts don't quote paths

Risk 53
Severity
7.8
EPSS
0.04%
First published (updated )

Python PythonRegular-expression DoS when parsing TarFile headers

Risk 47
Severity
7.5
First published (updated )

Python PythonQuadratic complexity parsing cookies with backslashes

Risk 32
Severity
7.5
EPSS
0.11%
First published (updated )

Python Pythontempfile.mkdtemp() may be readable and writeable by all users on Windows

Risk 39
Severity
7.1
EPSS
0.04%
First published (updated )

redhat/PythonRace Condition

Risk 52
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

redhat/PyhtonLast updated 24 July 2024

Risk 45
Severity
7.5
First published (updated )

Python PythonPython is vulnerable to a denial of service, caused by a RecursionError in email.utils.parseaddr #10…

Risk 45
Severity
7.5
First published (updated )

Python CPythonUse After Free

Risk 31
Severity
5.5
First published (updated )

Python PythonInput Validation, Null Pointer Dereference, Use After Free, Buffer Overflow, Integer Overflow

Risk 29
Severity
5.3
First published (updated )

Python PythonInput Validation

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203