Python Software Foundation CPython是Python Software Foundation基金会的编程语言解释器。 Python 3.15.0之前版本存在输入验证错误漏洞,该漏洞源于使用“configparser”模块写入包含回车字符(\r)的多行文本值的配置文件时,若攻击者控制写入值,可能注入意外键和值。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Python Software Foundation | CPython | < 3.10.21 |
affected |
3.11.0< 3.11.16 |
affected | ||
3.12.0< 3.12.14 |
affected | ||
3.13.0< 3.13.15 |
affected | ||
3.14.0< 3.14.7 |
affected | ||
3.15.0a1< 3.15.0b4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Python Software Foundation | CPython | 0 ~ 3.10.21 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11972 | 8.2 HIGH | tarfile opened in streaming mode mishandles EOF |
| CVE-2026-11940 | 7.8 HIGH | tarfile extraction filter bypass allows escaping the destination directory |
No comments yet