Where
-Infinity
0

Pillow PillowPillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`

Risk 54
Severity
8.2
First published (updated )

Pillow PillowPillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()

Risk 43
Severity
7.5
First published (updated )

PillowPillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images

Risk 43
Severity
7.5
First published (updated )

Pillow PillowPillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch

Risk 43
Severity
7.5
First published (updated )

Pillow PillowPillow EpsImagePlugin negative %%BeginBinary byte count causes infinite loop denial of service

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Pillow PillowPillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow

Risk 43
Severity
7.5
First published (updated )

pypi/PillowPillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service

Risk 47
Severity
8.7
First published (updated )

oss-sec[oss-security][CVE-2026-15308] Incmental HTMLParser allows CPU-exhaustion DoS via peated unterminated markup declarations

Python html.parser.HTMLParserIncremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations

Risk 50
Severity
8.7
First published (updated )

pypi/setuptoolssetuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+

Risk 41
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Pillow PillowPillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading

Risk 43
Severity
7.5
First published (updated )

Pillow PillowPillow GdImageFile decompression bomb protection bypass

Risk 43
Severity
7.5
First published (updated )

Pillow PillowPillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`

Risk 43
Severity
7.5
First published (updated )

Pillow PillowPillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading

Risk 43
Severity
7.5
First published (updated )

Pillow PillowPillow: WindowsViewer.get_command() OS command injection via unescaped shell path

Risk 34
Severity
4.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

python/tarfileTarfile.extract() doesn't fully respect filter parameter

Risk 27
Severity
2
First published (updated )

Python tarfile moduletarfile opened in streaming mode mishandles EOF

Risk 43
Severity
8.2
First published (updated )

Python configparserConfiguration Injection via Carriage Return (\r) in write() method

Risk 24
Severity
4.1
First published (updated )

oss-sec[oss-security][CVE-2026-11940] Cpython: tarfile extraction filter bypass allows escaping the destination dictory

Python CPythontarfile extraction filter bypass allows escaping the destination directory

Risk 68
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Python CPythonCPython >3.11 Insecure Input Validation resulting in privilege escalation

Risk 47
Severity
5.3
First published (updated )

oss-sec[oss-security][CVE-2026-9669] CPython: bz2.BZ2Decompssor use after error can cause a stack buffer overflow

oss-sec[oss-security][CVE-2026-7774] Cpython: tarfile.data_filter path traversal bypass allows writing outside the extraction dictory

Python CPythontarfile.data_filter path traversal bypass allows writing outside the extraction directory

Risk 44
Severity
6.9
First published (updated )

Python jsonpicklepython jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to exec…

Risk 89
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-sec[oss-security][CVE-2026-8328] CPython: FTP PASV SSRF, ftpcp() does not use actual peer addss, trusts server-supplied PASV host addss

Microsoft azl3 python3 3.12.9-11FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address

Risk 27
Severity
5.9
EPSS
0.07%
First published (updated )

oss-sec[oss-security][CVE-2026-7210] Cpython: The expat and elementte parsers use insufficient entropy for XML hash-flooding protection

Python Software Foundation CPythonThe expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

Risk 32
Severity
6.3
EPSS
0.06%
First published (updated )

IBM Engineering AI Huburllib3: Decompression-bomb safeguards bypassed in parts of the streaming API

Risk 46
Severity
8.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203