rpm package
opensuse/python3&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/python3&distro=openSUSE%20Leap%2016.0
Vulnerabilities (6)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-6019 | Med | 6.1 | < 3.13.14-160000.1.1 | 3.13.14-160000.1.1 | Apr 22, 2026 | http.cookies.Morsel.js_output() returns an inline inside the generated script element. Mitigation base64-encodes the cookie value to disallow esc | |
| CVE-2026-4786 | Hig | 7.1 | < 3.13.14-160000.1.1 | 3.13.14-160000.1.1 | Apr 13, 2026 | Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. | |
| CVE-2026-6100 | Hig | 8.1 | < 3.13.14-160000.1.1 | 3.13.14-160000.1.1 | Apr 13, 2026 | Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The | |
| CVE-2026-3446 | Med | — | < 3.13.14-160000.1.1 | 3.13.14-160000.1.1 | Apr 10, 2026 | When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other impleme | |
| CVE-2026-1502 | Med | — | < 3.13.14-160000.1.1 | 3.13.14-160000.1.1 | Apr 10, 2026 | CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. | |
| CVE-2021-4189 | Med | 5.3 | < 3.13.14-160000.1.1 | 3.13.14-160000.1.1 | Aug 24, 2022 | A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP |
- affected < 3.13.14-160000.1.1fixed 3.13.14-160000.1.1
http.cookies.Morsel.js_output() returns an inline inside the generated script element. Mitigation base64-encodes the cookie value to disallow esc
- affected < 3.13.14-160000.1.1fixed 3.13.14-160000.1.1
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
- affected < 3.13.14-160000.1.1fixed 3.13.14-160000.1.1
Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The
- affected < 3.13.14-160000.1.1fixed 3.13.14-160000.1.1
When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other impleme
- affected < 3.13.14-160000.1.1fixed 3.13.14-160000.1.1
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
- affected < 3.13.14-160000.1.1fixed 3.13.14-160000.1.1
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP