[CVE-2026-18503] Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()
by Seth Larson Aug. 10, 2026
by Seth Larson Aug. 10, 2026
Aug. 10, 2026
1
0
[CVE-2026-13346] pip absolute path traversal during download from malicious package indexes
by Seth Larson July 29, 2026
by Seth Larson July 29, 2026
July 29, 2026
1
0
CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates
by Petr Viktorin July 28, 2026
by Petr Viktorin July 28, 2026
July 28, 2026
1
0
[CVE-2026-15308] Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
by Seth Larson July 9, 2026
by Seth Larson July 9, 2026
July 9, 2026
1
0
[CVE-2026-4360] Tarfile.extract doesn't fully respect filter parameter
by Petr Viktorin June 30, 2026
by Petr Viktorin June 30, 2026
June 30, 2026
1
0
June 24, 2026
1
0
June 23, 2026
1
0
[CVE-2026-11940] tarfile extraction filter bypass allows escaping the destination directory
by Stan Ulbrych June 23, 2026
by Stan Ulbrych June 23, 2026
June 23, 2026
1
0
[CVE-2026-12003] In-tree (development) search paths can be enabled without modifying install directory
by Steve Dower June 16, 2026
by Steve Dower June 16, 2026
June 16, 2026
1
0
[CVE-2026-9669] bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
by Emma Smith June 8, 2026
by Emma Smith June 8, 2026
June 8, 2026
1
0