Where
-Infinity
0

oss-sec[oss-security][CVE-2026-12003] CPython In-te (development) search paths can be enabled without modifying install dictory

Python Software Foundation CPythonbz2.BZ2Decompressor reuse after error can cause a stack buffer overflow

Risk 31
Severity
8.2
EPSS
0.42%
First published (updated )

oss-sec[oss-security][CVE-2026-3276] Potential DoS via quadratic complexity in unicodedata.normalize()

oss-sec[oss-security][CVE-2026-7210] Cpython: The expat and elementte parsers use insufficient entropy for XML hash-flooding protection

Python Software Foundation CPythonThe expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

Risk 32
Severity
6.3
EPSS
0.06%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-sec[oss-security][CVE-2026-3087] shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

Python Software Foundation CPythonOut-of-bounds read/write during remote profiling and asyncio process introspection when connecting to malicious target

Risk 32
Severity
5.3
EPSS
0.02%
First published (updated )

Python Software Foundation CPythonIncomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

Risk 46
Severity
7
EPSS
0.02%
First published (updated )

Python Software Foundation CPythonUse-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure

Risk 46
Severity
9.1
EPSS
0.15%
First published (updated )

oss-secCPython [CVE-2026-3446] Base64 decoding stops at first padded quad by default

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Python Software Foundation CPythonBase64 decoding stops at first padded quad by default

Risk 33
Severity
6
First published (updated )

Python Software Foundation CPythonHTTP client proxy tunnel headers not validated for CR/LF

Risk 32
Severity
5.7
First published (updated )

Python Pythonwebbrowser.open() allows leading dashes in URLs

Risk 46
Severity
7
EPSS
0.03%
First published (updated )

Python Software Foundation CPythonThe import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly han…

Risk 5
Severity
1
First published (updated )

Python Software Foundation CPythonThere is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enume…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

jaraco zippA Denial of Service (DoS) vulnerability exists in the jaraco/zipp library, affecting all versions pr…

Risk 18
Severity
4
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203