Python

Cpython

71 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 30.09.2026 16:17:39
  • Zuletzt bearbeitet 03.10.2026 01:17:25

ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification wo...

  • EPSS 0.43%
  • Veröffentlicht 30.09.2026 16:16:04
  • Zuletzt bearbeitet 03.10.2026 01:17:24

A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the ...

  • EPSS 0.18%
  • Veröffentlicht 29.09.2026 17:46:01
  • Zuletzt bearbeitet 03.10.2026 01:17:23

The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have thei...

  • EPSS 0.18%
  • Veröffentlicht 14.09.2026 19:17:50
  • Zuletzt bearbeitet 02.10.2026 01:16:44

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a fil...

  • EPSS 0.42%
  • Veröffentlicht 11.09.2026 17:27:04
  • Zuletzt bearbeitet 03.10.2026 01:17:25

When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the l...

  • EPSS 0.3%
  • Veröffentlicht 25.08.2026 15:16:30
  • Zuletzt bearbeitet 02.10.2026 01:16:43

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.

  • EPSS 0.32%
  • Veröffentlicht 19.08.2026 15:24:08
  • Zuletzt bearbeitet 28.08.2026 21:16:15

The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but in...

  • EPSS 0.36%
  • Veröffentlicht 18.08.2026 15:50:57
  • Zuletzt bearbeitet 02.10.2026 01:16:43

The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Cre...

  • EPSS 0.51%
  • Veröffentlicht 18.08.2026 13:57:31
  • Zuletzt bearbeitet 02.10.2026 01:16:43

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain name...

  • EPSS 0.11%
  • Veröffentlicht 10.08.2026 13:45:31
  • Zuletzt bearbeitet 18.08.2026 15:04:46

Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().