Bénédikt Tran (https://github.com/picnixz)
4 credited records · 4 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2026-19553Proof of concept | SSLContext.wrap_bio() missing validation of server_hostname parameterpython software foundation · cpython · CWE-297 | High7.6 | — | 0.4% | Sep 30, 2026 |
36Monitor | CVE-2026-19445Proof of concept | Use-after-free of a server-side SSLContext when sni_callback switches contextspython software foundation · cpython · CWE-416 | Critical9.2 | — | 0.4% | Sep 30, 2026 |
25Monitor | CVE-2026-3276No exploit | Potential DoS via quadratic complexity in unicodedata.normalize()python software foundation · cpython · CWE-407 | Medium6.3 | — | 0.7% | Jun 3, 2026 |
23Monitor | CVE-2026-8328No exploit | FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host addresspython software foundation · cpython · CWE-918 | Medium5.9 | — | 0.7% | May 13, 2026 |
- CVE-2026-1955330Monitor
SSLContext.wrap_bio() missing validation of server_hostname parameter
HighCVSS 7.6Proof of conceptEPSS 0%python software foundation · cpythonSep 30, 2026
- CVE-2026-1944536Monitor
Use-after-free of a server-side SSLContext when sni_callback switches contexts
CriticalCVSS 9.2Proof of conceptEPSS 0%python software foundation · cpythonSep 30, 2026
- CVE-2026-327625Monitor
Potential DoS via quadratic complexity in unicodedata.normalize()
MediumCVSS 6.3No exploitEPSS 1%python software foundation · cpythonJun 3, 2026
- CVE-2026-832823Monitor
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
MediumCVSS 5.9No exploitEPSS 1%python software foundation · cpythonMay 13, 2026