| python3-dev |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-7210
- The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
|
5/11/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-7210
- The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
|
5/11/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2026-6019
- BaseCookie.js_output() does not neutralize embedded characters
|
4/22/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2026-6019
- BaseCookie.js_output() does not neutralize embedded characters
|
4/22/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
High
|
CVE-2026-4519
- webbrowser.open() allows leading dashes in URLs
|
3/20/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
High
|
CVE-2026-4519
- webbrowser.open() allows leading dashes in URLs
|
3/20/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-4224
- Stack overflow parsing XML with deeply nested DTD content models
|
3/16/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-4224
- Stack overflow parsing XML with deeply nested DTD content models
|
3/16/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-3644
- Incomplete control character validation in http.cookies
|
3/16/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-3644
- Incomplete control character validation in http.cookies
|
3/16/2026 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-3087
- shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
|
4/27/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2026-3087
- shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
|
4/27/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2025-6075
- Quadratic complexity in os.path.expandvars() with user-controlled template
|
10/31/2025 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2025-6075
- Quadratic complexity in os.path.expandvars() with user-controlled template
|
10/31/2025 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2025-13837
- Out-of-memory when loading Plist
|
12/1/2025 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2025-13837
- Out-of-memory when loading Plist
|
12/1/2025 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2025-13836
- Excessive read buffering DoS in http.client
|
12/1/2025 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Medium
|
CVE-2025-13836
- Excessive read buffering DoS in http.client
|
12/1/2025 |
| python3-dev |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2025-13462
- tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling
|
3/12/2026 |
| python3-devel |
py.1.0
|
Python Software Foundation
|
Low
|
CVE-2025-13462
- tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling
|
3/12/2026 |