Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Python Software Foundation — Vulnerabilities & Security Advisories 76

Browse all 76 CVE security advisories affecting Python Software Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The Python Software Foundation (PSF) is a non-profit organization dedicated to protecting and advancing the Python programming language while supporting and facilitating the growth of a diverse global community of developers. As the steward of the official Python distribution, its core business involves maintaining the integrity of the interpreter and standard library, which are foundational to countless enterprise and scientific applications. Historically, vulnerabilities associated with the PSF’s maintained codebase have frequently involved memory corruption issues, such as buffer overflows, and logic flaws leading to privilege escalation or remote code execution (RCE) within the interpreter itself. While the PSF does not host third-party packages, its official releases have occasionally been targeted by supply chain attacks or misconfigurations in associated infrastructure. Notable incidents include critical flaws in the SSL/TLS handling and integer overflow bugs in the standard library, prompting rigorous security audits and rapid patch cycles to mitigate risks for the vast ecosystem relying on Python’s core infrastructure.

Top products by Python Software Foundation: CPython pymanager
CVE ID Title CVSS Severity Published
CVE-2025-0938 URL parser allowed square brackets in domain names — CPython CWE-20 6.3 Medium 2025-01-31
CVE-2024-12254 Unbounded memory buffering in SelectorSocketTransport.writelines() — CPython CWE-400 8.7 High 2024-12-06
CVE-2024-11168 Improper validation of IPv6 and IPvFuture addresses — CPython 9.1 - 2024-11-12
CVE-2024-9287 Virtual environment (venv) activation scripts don't quote paths — CPython CWE-428 10.0AI Critical AI 2024-10-22
CVE-2024-6232 Regular-expression DoS when parsing TarFile headers — CPython CWE-1333 6.5 - 2024-09-03
CVE-2024-8088 Infinite loop when iterating over zip archive entry names from zipfile.Path — CPython CWE-835 6.5 - 2024-08-22
CVE-2024-7592 Quadratic complexity parsing cookies with backslashes — CPython CWE-400 5.3 - 2024-08-19
CVE-2024-6923 Email header injection due to unquoted newlines — CPython 4.3 - 2024-08-01
CVE-2024-3219 Pure-Python fallback of socket.socketpair() doesn’t authenticate peer connection — CPython 6.3AI Medium AI 2024-07-29
CVE-2024-5642 Buffer overread when using an empty list with SSLContext.set_npn_protocols() — CPython - - AI 2024-06-27
CVE-2024-0397 Memory race condition in ssl.SSLContext certificate store methods — CPython 7.4AI High AI 2024-06-17
CVE-2024-4032 Incorrect IPv4 and IPv6 private ranges — CPython 7.5AI High AI 2024-06-17
CVE-2024-4030 tempfile.mkdtemp() may be readable and writeable by all users on Windows — CPython CWE-276 7.1AI High AI 2024-05-07
CVE-2023-6597 Python 安全漏洞 — CPython 7.8 High 2024-03-19
CVE-2024-0450 Quoted zip-bomb protection for zipfile — CPython CWE-405 6.2 Medium 2024-03-19
CVE-2023-6507 Groups not dropped before running subprocess when using empty 'extra_groups' parameter — CPython CWE-269 6.1 Medium 2023-12-08

This page lists every published CVE security advisory associated with Python Software Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.