Where
-Infinity
0

oss-sec[oss-security][CVE-2026-12003] CPython In-te (development) search paths can be enabled without modifying install dictory

Python Software Foundation CPythonbz2.BZ2Decompressor reuse after error can cause a stack buffer overflow

Risk 31
Severity
8.2
EPSS
0.42%
First published (updated )

oss-sec[oss-security][CVE-2026-3276] Potential DoS via quadratic complexity in unicodedata.normalize()

Python Software Foundation PythonPotential DoS via quadratic complexity in unicodedata.normalize()

Risk 30
Severity
6.3
First published (updated )

oss-sec[oss-security][CVE-2026-7210] Cpython: The expat and elementte parsers use insufficient entropy for XML hash-flooding protection

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Python PythonThe expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

Risk 32
Severity
6.3
EPSS
0.06%
First published (updated )

oss-sec[oss-security][CVE-2026-3087] shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

Python Software Foundation PythonThe "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "pyt…

Risk 19
Severity
4
First published (updated )

Python Software Foundation CPythonOut-of-bounds read/write during remote profiling and asyncio process introspection when connecting to malicious target

Risk 32
Severity
5.3
EPSS
0.02%
First published (updated )

Python Software Foundation CPythonIncomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

Risk 46
Severity
7
EPSS
0.02%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Python Software Foundation CPythonUse-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

Risk 46
Severity
9.1
EPSS
0.15%
First published (updated )

oss-secCPython [CVE-2026-3446] Base64 decoding stops at first padded quad by default

First published (updated )

Python Software Foundation CPythonBase64 decoding stops at first padded quad by default

Risk 33
Severity
6
First published (updated )

Python Software Foundation CPythonHTTP client proxy tunnel headers not validated for CR/LF

Risk 32
Severity
5.7
First published (updated )

Python Pythonwebbrowser.open() allows leading dashes in URLs

Risk 46
Severity
7
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Python Software Foundation CPython (http.cookies)Input Validation

Risk 19
Severity
4
First published (updated )

Python Software Foundation CPythonThe import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly han…

Risk 5
Severity
1
First published (updated )

Python Software Foundation Python plistlibWhen loading a plist file, the plistlib module reads data in size specified by the file itself, mean…

Risk 19
Severity
4
First published (updated )

Python PythonOut-of-memory when loading Plist

Risk 34
Severity
2.1
First published (updated )

Python Software Foundation python-ldappython-ldap Vulnerable to Improper Encoding or Escaping of Output and Improper Null Termination

Risk 28
Severity
5.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Python Software Foundation Python 3.14End of life details

EOL
Oct 31, 2030
Support Ends
Oct 1, 2027
First published (updated )

The RegisterNew string of phishing attacks targets Python developers

First published (updated )

Python Software Foundation pipFallback tar extraction in pip doesn't check symbolic links point to extraction directory

Risk 26
Severity
5.9
EPSS
0.02%
First published (updated )

BleepingComputerPyPI urges users to reset credentials after new phishing attacks

First published (updated )

BleepingComputerPyPI invalidates tokens stolen in GhostAction supply chain attack

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerHackers target Python devs in phishing attacks using fake PyPI site

First published (updated )

Fwd:[CVE-2025-8194] Cpython Tarfile infinite loop during parsing with negative member offset

First published (updated )

Python Software Foundation CPythonThere is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enume…

Risk 19
Severity
4
First published (updated )

CPython: Multiple CVEs (1 CRITICAL, 3 HIGH, 1 MODERATE) affecting the tarfile module

CVE-2024-47081: Netrc cdential leak in PSF quests library

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203