Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Python Software Foundation — Vulnerabilities & Security Advisories 76

Browse all 76 CVE security advisories affecting Python Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Python Software Foundation (PSF) is a non-profit organization dedicated to protecting and advancing the Python programming language while supporting and facilitating the growth of a diverse global community of developers. As the steward of the official Python distribution, its core business involves maintaining the integrity of the interpreter and standard library, which are foundational to countless enterprise and scientific applications. Historically, vulnerabilities associated with the PSF’s maintained codebase have frequently involved memory corruption issues, such as buffer overflows, and logic flaws leading to privilege escalation or remote code execution (RCE) within the interpreter itself. While the PSF does not host third-party packages, its official releases have occasionally been targeted by supply chain attacks or misconfigurations in associated infrastructure. Notable incidents include critical flaws in the SSL/TLS handling and integer overflow bugs in the standard library, prompting rigorous security audits and rapid patch cycles to mitigate risks for the vast ecosystem relying on Python’s core infrastructure.

Top products by Python Software Foundation: CPython pymanager
CVE ID Title CVSS Severity Published
CVE-2026-5271 Possible to hijack modules in current working directory — pymanager 8.4AI High AI 2026-04-01
CVE-2026-4519 webbrowser.open() allows leading dashes in URLs — CPython 7.0 High 2026-03-20
CVE-2026-3479 pkgutil.get_data() does not enforce documented restrictions — CPython 7.5 - 2026-03-18
CVE-2026-4224 Stack overflow parsing XML with deeply nested DTD content models — CPython 6.0 Medium 2026-03-16
CVE-2026-3644 Incomplete control character validation in http.cookies — CPython 6.0 Medium 2026-03-16
CVE-2025-13462 tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling — CPython 2.0 Low 2026-03-12
CVE-2026-2297 SourcelessFileLoader does not use io.open_code() — CPython 5.7 Medium 2026-03-04
CVE-2026-1299 email BytesGenerator header injection due to unquoted newlines — CPython CWE-93 4.3 - 2026-01-23
CVE-2025-12781 base64.b64decode() always accepts "+/" characters, despite setting altchars — CPython 7.5AI High AI 2026-01-21
CVE-2026-0672 Header injection in http.cookies.Morsel — CPython CWE-93 4.3AI Medium AI 2026-01-20
CVE-2025-15367 POP3 command injection in user-controlled commands — CPython CWE-77 9.8AI Critical AI 2026-01-20
CVE-2025-15366 IMAP command injection in user-controlled commands — CPython CWE-77 5.9 Medium 2026-01-20
CVE-2025-15282 Header injection via newlines in data URL mediatype — CPython CWE-93 5.3AI Medium AI 2026-01-20
CVE-2026-0865 wsgiref.headers.Headers allows header newline injection — CPython CWE-74 4.7AI Medium AI 2026-01-20
CVE-2025-11468 Folding email comments of unfoldable characters doesn't preserve parenthesis — CPython 6.5AI Medium AI 2026-01-20
CVE-2025-12084 Quadratic complexity in node ID cache clearing — CPython 7.5AI High AI 2025-12-03
CVE-2025-13837 Out-of-memory when loading Plist — CPython 6.5AI Medium AI 2025-12-01
CVE-2025-13836 Excessive read buffering DoS in http.client — CPython 9.8AI Critical AI 2025-12-01
CVE-2025-6075 Quadratic complexity in os.path.expandvars() with user-controlled template — CPython 1.8 Low 2025-10-31
CVE-2025-8291 ZIP64 End of Central Directory (EOCD) Locator record offset not checked — CPython 4.3 Medium 2025-10-07
CVE-2025-8194 Tarfile infinite loop during parsing with negative member offset — CPython CWE-835 7.5 High 2025-07-28
CVE-2025-6069 HTMLParser quadratic complexity when processing malformed inputs — CPython CWE-1333 4.3 Medium 2025-06-17
CVE-2024-12718 Bypass extraction filter to modify file metadata outside extraction directory — CPython CWE-22 5.3 Medium 2025-06-03
CVE-2025-4435 Tarfile extracts filtered members when errorlevel=0 — CPython 7.5 High 2025-06-03
CVE-2025-4138 Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory — CPython CWE-22 7.5 High 2025-06-03
CVE-2025-4330 Extraction filter bypass for linking outside extraction directory — CPython CWE-22 7.5 High 2025-06-03
CVE-2025-4517 Arbitrary writes via tarfile realpath overflow — CPython CWE-22 9.4 Critical 2025-06-03
CVE-2025-4516 Use-after-free in "unicode_escape" decoder with error handler — CPython CWE-416 5.9 Medium 2025-05-15
CVE-2025-1795 Mishandling of comma during folding and unicode-encoding of email headers — CPython 2.3 Low 2025-02-28
CVE-2024-3220 Default mimetype known files writeable on Windows — CPython CWE-426 5.5 - 2025-02-14

This page lists every published CVE security advisory associated with Python Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.