python
27 known vulnerabilities affecting python products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-54058 | High | 0.5% | 9.1 | Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncomp… | |
| CVE-2026-21441 | Medium | 3.0% | 7.5 | urllib3 is an HTTP client library for Python. urllib3's streaming API is designe… | |
| CVE-2025-13836 | Medium | 1.6% | 7.5 | When reading an HTTP response from a server, if no read amount is specified, the… | |
| CVE-2026-4224 | Medium | 0.7% | 7.5 | When an Expat parser with a registered ElementDeclHandler parses an inline docum… | |
| CVE-2026-44432 | Medium | 0.7% | 7.5 | urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib… | |
| CVE-2026-7210 | Medium | 0.7% | 7.5 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Exp… | |
| CVE-2026-40192 | Medium | 0.7% | 7.5 | Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit… | |
| CVE-2026-15308 | Medium | 0.6% | 7.5 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-se… | |
| CVE-2026-32274 | Medium | 0.6% | 7.5 | Black is the uncompromising Python code formatter. Starting in version 24.3.0 an… | |
| CVE-2026-3087 | Medium | 0.6% | 7.5 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows pat… | |
| CVE-2026-3644 | Medium | 0.5% | 7.5 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Mor… | |
| CVE-2026-59197 | Medium | 0.4% | 8.2 | Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter… | |
| CVE-2026-59204 | Medium | 0.4% | 7.5 | Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jp… | |
| CVE-2026-59200 | Medium | 0.4% | 7.5 | Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream… | |
| CVE-2026-25990 | Medium | 0.4% | 7.5 | Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-boun… | |
| CVE-2026-42311 | Medium | 0.2% | 7.8 | Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0… | |
| CVE-2023-6507 | Low | 1.3% | 6.1 | An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The… | |
| CVE-2026-4519 | Low | 0.3% | 3.3 | The webbrowser.open() API would accept leading dashes in the URL which could be… | |
| CVE-2026-4360 | Low | 0.3% | 5.3 | In the Tarfile.extract() function, the filter parameter is not passed properly w… | |
| CVE-2026-6019 | Low | 0.2% | 6.1 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only esca… | |
| CVE-2025-13837 | Low | 0.2% | 5.5 | When loading a plist file, the plistlib module reads data in size specified by t… | |
| CVE-2025-13462 | Low | 0.2% | 3.3 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks t… | |
| CVE-2025-6075 | Low | 0.1% | 5.5 | If the value passed to os.path.expandvars() is user-controlled a performance de… | |
| CVE-2026-42309 | Low | 0.1% | 5.5 | Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0… | |
| CVE-2026-0864 | Low | 0.1% | 5.5 | When using the "configparser" module to write configuration files containing mul… | |
| CVE-2026-42310 | Low | 0.1% | 5.5 | Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0,… | |
| CVE-2026-42308 | Low | 0.1% | 5.5 | Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances … |