[CVE-2026-13346] pip absolute path traversal during download from malicious package indexes
by Seth Larson July 29, 2026
by Seth Larson July 29, 2026
July 29, 2026
1
0
CVE-2026-6879 Quadratic Behavior in xml.etree.ElementPath Index Predicates
by Petr Viktorin July 28, 2026
by Petr Viktorin July 28, 2026
July 28, 2026
1
0
[CVE-2026-15308] Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
by Seth Larson July 9, 2026
by Seth Larson July 9, 2026
July 9, 2026
1
0
[CVE-2026-4360] Tarfile.extract doesn't fully respect filter parameter
by Petr Viktorin June 30, 2026
by Petr Viktorin June 30, 2026
June 30, 2026
1
0
June 23, 2026
1
0
June 23, 2026
1
0
[CVE-2026-11940] tarfile extraction filter bypass allows escaping the destination directory
by Stan Ulbrych June 23, 2026
by Stan Ulbrych June 23, 2026
June 23, 2026
1
0
[CVE-2026-12003] In-tree (development) search paths can be enabled without modifying install directory
by Steve Dower June 16, 2026
by Steve Dower June 16, 2026
June 16, 2026
1
0
[CVE-2026-9669] bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
by Emma Smith June 8, 2026
by Emma Smith June 8, 2026
June 8, 2026
1
0
[CVE-2026-7774] tarfile.data_filter path traversal bypass allows writing outside the extraction directory
by Stan Ulbrych June 4, 2026
by Stan Ulbrych June 4, 2026
June 4, 2026
1
0