| python3-devel |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-7210
- The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
|
5/11/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-7210
- The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
|
5/11/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2026-6019
- BaseCookie.js_output() does not neutralize embedded characters
|
4/22/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2026-6019
- BaseCookie.js_output() does not neutralize embedded characters
|
4/22/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
High
|
CVE-2026-4519
- webbrowser.open() allows leading dashes in URLs
|
3/20/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
High
|
CVE-2026-4519
- webbrowser.open() allows leading dashes in URLs
|
3/20/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2026-4360
- Tarfile.extract() doesn't fully respect filter parameter
|
6/30/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2026-4360
- Tarfile.extract() doesn't fully respect filter parameter
|
6/30/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-4224
- Stack overflow parsing XML with deeply nested DTD content models
|
3/16/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-4224
- Stack overflow parsing XML with deeply nested DTD content models
|
3/16/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-3644
- Incomplete control character validation in http.cookies
|
3/16/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-3644
- Incomplete control character validation in http.cookies
|
3/16/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-3087
- shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
|
4/27/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-3087
- shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
|
4/27/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
High
|
CVE-2026-15308
- Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
|
7/9/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
High
|
CVE-2026-15308
- Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
|
7/9/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2025-6075
- Quadratic complexity in os.path.expandvars() with user-controlled template
|
10/31/2025 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2025-6075
- Quadratic complexity in os.path.expandvars() with user-controlled template
|
10/31/2025 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2025-13837
- Out-of-memory when loading Plist
|
12/1/2025 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2025-13837
- Out-of-memory when loading Plist
|
12/1/2025 |