Cpython
This hub aggregates every CVE we track for Cpython, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
76
CVEs tracked
3
Critical
24
High
0
In CISA KEV
Severity distribution
HIGH24MEDIUM24LOW4CRITICAL3
Monthly trend
1
1
1
1
2
0
0
1
6
1
0
0
2
1
3
8
0
6
8
2
9
2
5
2
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Cpython.
- CVE-2026-82049tarfile extraction filters allow file modification and content disclosure via hard link to symlink
- CVE-2026-87910tarfile hardlink fallback ignores custom extraction filter rejection via None
- CVE-2026-15310zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
- CVE-2026-19672tarfile extraction filter bypass allows creation of directories outside the destination
- CVE-2026-15806`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching
- CVE-2026-17084stringprep.map_table_b2() deviates from RFC 3454 Table B.2
- CVE-2026-18503Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()
- CVE-2026-6879Quadratic Behavior in xml.etree.ElementPath Index Predicates
- CVE-2026-15308Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations7.5
- CVE-2026-4360Tarfile.extract() doesn't fully respect filter parameter5.3
- CVE-2026-11972tarfile opened in streaming mode mishandles EOF
- CVE-2026-0864Configuration Injection via Carriage Return (\r) in write() method5.5
- CVE-2026-11940tarfile extraction filter bypass allows escaping the destination directory
- BDU:2026-08551Уязвимость функции ast_for_if_stmt() интерпретатора языка программирования Python (CPython), связанная с ошибками разыменования указателей, позволяющая нарушителю вызвать отказ в обслуживании5.5
- CVE-2026-12003CPython >3.11 Insecure Input Validation resulting in privilege escalation
Product normalization is registry-driven with AI assist and human review. How it works