VYPR

Python

by Python (programming language)

Source repositories

CVEs (204)

  • CVE-2020-27619CriOct 22, 2020
    risk 0.01cvss 9.8epss 0.08

    In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.

  • CVE-2020-8492MedJan 30, 2020
    risk 0.01cvss 6.5epss 0.07

    Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic…

  • CVE-2019-15903HigSep 4, 2019
    risk 0.01cvss 7.5epss 0.07

    In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

  • CVE-2019-9948CriMar 23, 2019
    risk 0.01cvss 9.1epss 0.12

    urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.

  • CVE-2019-9636CriMar 8, 2019
    risk 0.01cvss 9.8epss 0.09

    Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The…

  • CVE-2008-1887Apr 18, 2008
    risk 0.01cvss —epss 0.06

    Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers…

  • CVE-2026-3479NonMar 18, 2026
    risk 0.00cvss —epss 0.00

    DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security…

  • CVE-2025-12781MedJan 21, 2026
    risk 0.00cvss 5.3epss 0.01

    When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alternative base64 alphabet" such as…

  • CVE-2025-12084MedDec 3, 2025
    risk 0.00cvss 5.3epss 0.01

    When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.

  • CVE-2024-9287HigOct 22, 2024
    risk 0.00cvss 7.8epss 0.01

    A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This…

  • CVE-2024-6232HigSep 3, 2024
    risk 0.00cvss 7.5epss 0.02

    There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

  • CVE-2024-7592HigAug 19, 2024
    risk 0.00cvss 7.5epss 0.02

    There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting…

  • CVE-2023-41105HigAug 23, 2023
    risk 0.00cvss 7.5epss 0.03

    An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security…

  • CVE-2023-33595MedJun 7, 2023
    risk 0.00cvss 5.5epss 0.00

    CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c.

  • CVE-2021-4189MedAug 24, 2022
    risk 0.00cvss 5.3epss 0.03

    A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP…

  • CVE-2021-28861HigAug 23, 2022
    risk 0.00cvss 7.4epss 0.03

    Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html…

  • CVE-2021-3733MedMar 10, 2022
    risk 0.00cvss 6.5epss 0.05

    There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially…

  • CVE-2020-15801CriJul 17, 2020
    risk 0.00cvss 9.8epss 0.03

    In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The ._pth file (e.g., the python._pth file) is not affected.

  • CVE-2020-15523HigJul 4, 2020
    risk 0.00cvss 7.8epss 0.01

    In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for…

  • CVE-2019-16056HigSep 6, 2019
    risk 0.00cvss 7.5epss 0.05

    An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on…

Page 8 of 11