[CVE-2026-4360] Tarfile.extract doesn't fully respect filter parameter
by Petr Viktorin June 30, 2026
by Petr Viktorin June 30, 2026
June 30, 2026
1
0
June 23, 2026
1
0
June 23, 2026
1
0
[CVE-2026-11940] tarfile extraction filter bypass allows escaping the destination directory
by Stan Ulbrych June 23, 2026
by Stan Ulbrych June 23, 2026
June 23, 2026
1
0
[CVE-2026-12003] In-tree (development) search paths can be enabled without modifying install directory
by Steve Dower June 16, 2026
by Steve Dower June 16, 2026
June 16, 2026
1
0
[CVE-2026-9669] bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
by Emma Smith June 8, 2026
by Emma Smith June 8, 2026
June 8, 2026
1
0
[CVE-2026-7774] tarfile.data_filter path traversal bypass allows writing outside the extraction directory
by Stan Ulbrych June 4, 2026
by Stan Ulbrych June 4, 2026
June 4, 2026
1
0
[CVE-2026-3276] Potential DoS via quadratic complexity in unicodedata.normalize()
by Stan Ulbrych June 3, 2026
by Stan Ulbrych June 3, 2026
June 3, 2026
1
0
[CVE-2026-8643] pip can extract console_scripts and gui_scripts outside installation directory
by Seth Larson June 1, 2026
by Seth Larson June 1, 2026
June 1, 2026
1
0