Python Software Foundation CPython

20 known vulnerabilities in Python Software Foundation CPython, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-19553 CVSS 7.6 high ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a…
  • CVE-2026-19445 CVSS 9.2 critical A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different…
  • CVE-2026-12345 CVSS 5.9 medium The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can…
  • CVE-2026-82049 CVSS 8.4 high In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard…
  • CVE-2026-87910 CVSS 5.7 medium When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case…
  • CVE-2026-15310 CVSS 2.1 low When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to…
  • CVE-2026-19672 CVSS 6.3 medium The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the…
  • CVE-2026-15806 CVSS 6.0 medium The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and…
  • CVE-2026-17084 CVSS 6.0 medium The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were…
  • CVE-2026-18503 CVSS 2.4 low Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when…
  • CVE-2026-6879 CVSS 2.0 low `Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index predicates (e.g…
  • CVE-2026-15308 CVSS 8.7 high The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations…
  • CVE-2026-4360 CVSS 2.0 low In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts…
  • CVE-2026-11972 CVSS 8.2 high When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making…
  • CVE-2026-0864 CVSS 4.1 medium When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r)…
  • CVE-2026-11940 CVSS 7.8 high tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored…
  • CVE-2026-12003 CVSS 5.3 medium To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build…
  • CVE-2025-15367 CVSS 5.9 medium The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects…
  • CVE-2025-15366 CVSS 5.9 medium The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects…
  • CVE-2025-4330 CVSS 7.5 high Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of…