Python

Cpython

35 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 23.01.2026 16:27:13
  • Zuletzt bearbeitet 26.01.2026 15:16:07

The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeade...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 21.01.2026 19:34:47
  • Zuletzt bearbeitet 02.02.2026 17:25:23

When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alterna...

  • EPSS 0.08%
  • Veröffentlicht 20.01.2026 21:52:33
  • Zuletzt bearbeitet 26.01.2026 15:16:07

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.

  • EPSS 0.06%
  • Veröffentlicht 20.01.2026 21:47:09
  • Zuletzt bearbeitet 26.01.2026 15:05:23

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

  • EPSS 0.06%
  • Veröffentlicht 20.01.2026 21:40:24
  • Zuletzt bearbeitet 26.01.2026 15:05:23

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

  • EPSS 0.08%
  • Veröffentlicht 20.01.2026 21:35:13
  • Zuletzt bearbeitet 26.01.2026 15:16:06

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.

  • EPSS 0.09%
  • Veröffentlicht 20.01.2026 21:26:15
  • Zuletzt bearbeitet 26.01.2026 15:05:23

User-controlled header names and values containing newlines can allow injecting HTTP headers.

  • EPSS 0.06%
  • Veröffentlicht 20.01.2026 21:09:11
  • Zuletzt bearbeitet 02.02.2026 23:15:57

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

  • EPSS 0.09%
  • Veröffentlicht 03.12.2025 18:55:32
  • Zuletzt bearbeitet 26.01.2026 15:16:05

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.

  • EPSS 0.02%
  • Veröffentlicht 01.12.2025 18:16:04
  • Zuletzt bearbeitet 15.01.2026 19:08:31

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues