Python

Python

143 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 12.03.2026 18:16:21
  • Zuletzt bearbeitet 13.08.2026 01:16:50

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the...

Exploit
  • EPSS 0.53%
  • Veröffentlicht 21.01.2026 19:34:47
  • Zuletzt bearbeitet 02.02.2026 17:25:23

When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alterna...

  • EPSS 0.78%
  • Veröffentlicht 03.12.2025 18:55:32
  • Zuletzt bearbeitet 26.01.2026 15:16:05

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.

  • EPSS 1.59%
  • Veröffentlicht 01.12.2025 18:16:04
  • Zuletzt bearbeitet 03.09.2026 03:15:20

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server to cause the client to read large amounts of data into memory, potentially causing OOM or ...

  • EPSS 0.22%
  • Veröffentlicht 01.12.2025 18:16:04
  • Zuletzt bearbeitet 03.09.2026 03:15:21

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

  • EPSS 0.14%
  • Veröffentlicht 31.10.2025 16:41:34
  • Zuletzt bearbeitet 07.10.2026 21:10:00

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

  • EPSS 0.58%
  • Veröffentlicht 30.10.2025 17:15:37
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python's tarfile.extractall function without the filter="data" feature. A remote attacker can c...

  • EPSS 0.44%
  • Veröffentlicht 24.09.2025 15:15:41
  • Zuletzt bearbeitet 26.09.2026 00:10:00

When extracting a tar archive pip may not check symbolic links point into the extraction directory if the tarfile module doesn't implement PEP 706. Note that upgrading pip to a "fixed" version for this vulnerability doesn't fix all known vulnerabilit...

  • EPSS 0.65%
  • Veröffentlicht 22.10.2024 17:15:06
  • Zuletzt bearbeitet 03.11.2025 23:17:33

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "sou...

Exploit
  • EPSS 2.2%
  • Veröffentlicht 03.09.2024 13:15:05
  • Zuletzt bearbeitet 03.11.2025 23:17:30

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.