Gregory P. Smith (https://github.com/gpshead)
5 записей с упоминанием · 5 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2026-19445Эксплойта нет | Use-after-free of a server-side SSLContext when sni_callback switches contextspython software foundation · cpython · CWE-416 | Критическая9,2 | — | — | Сегодня |
34Наблюдать | CVE-2026-15308Эксплойта нет | Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarationspython · python · CWE-400 | Высокая8,7 | — | 0,6 % | 9 июл. 2026 г. |
27Наблюдать | CVE-2026-7774Эксплойта нет | tarfile.data_filter path traversal bypass allows writing outside the extraction directorypython software foundation · cpython · CWE-22 | Средняя6,9 | — | 0,8 % | 4 июн. 2026 г. |
16Наблюдать | CVE-2026-8643Эксплойта нет | pip can extract console_scripts and gui_scripts outside installation directorypypa · pip · CWE-22 | Средняя4,1 | — | 0,5 % | 1 июн. 2026 г. |
23Наблюдать | CVE-2026-8328Эксплойта нет | FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host addresspython software foundation · cpython · CWE-918 | Средняя5,9 | — | 0,7 % | 13 мая 2026 г. |
25Наблюдать | CVE-2026-7210Эксплойта нет | The expat and elementtree parsers use insufficient entropy for XML hash-flooding protectionpython · python · CWE-331 | Средняя6,3 | — | 1,4 % | 11 мая 2026 г. |
- CVE-2026-1944536Наблюдать
Use-after-free of a server-side SSLContext when sni_callback switches contexts
КритическаяCVSS 9,2Эксплойта нетpython software foundation · cpythonСегодня
- CVE-2026-1530834Наблюдать
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %python · python9 июл. 2026 г.
- CVE-2026-777427Наблюдать
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
СредняяCVSS 6,9Эксплойта нетEPSS 1 %python software foundation · cpython4 июн. 2026 г.
- CVE-2026-864316Наблюдать
pip can extract console_scripts and gui_scripts outside installation directory
СредняяCVSS 4,1Эксплойта нетEPSS 0 %pypa · pip1 июн. 2026 г.
- CVE-2026-832823Наблюдать
FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
СредняяCVSS 5,9Эксплойта нетEPSS 1 %python software foundation · cpython13 мая 2026 г.
- CVE-2026-721025Наблюдать
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
СредняяCVSS 6,3Эксплойта нетEPSS 1 %python · python11 мая 2026 г.