Skip to content
Noroxi

Petr Viktorin (https://github.com/encukou)

13 credited records · 13 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory

    MediumCVSS 5.9No exploit

    python software foundation · cpython1 day ago

  • tarfile extraction filters allow file modification and content disclosure via hard link to symlink

    HighCVSS 8.4No exploitEPSS 0%

    python software foundation · cpythonSep 14, 2026

  • tarfile hardlink fallback ignores custom extraction filter rejection via None

    MediumCVSS 5.7No exploitEPSS 1%

    python software foundation · cpythonSep 11, 2026

  • zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits

    LowCVSS 2.1No exploitEPSS 1%

    python software foundation · cpythonAug 25, 2026

  • tarfile extraction filter bypass allows creation of directories outside the destination

    MediumCVSS 6.3No exploitEPSS 1%

    python software foundation · cpythonAug 19, 2026

  • stringprep.map_table_b2() deviates from RFC 3454 Table B.2

    MediumCVSS 6.0No exploitEPSS 1%

    python software foundation · cpythonAug 18, 2026

  • Quadratic Behavior in xml.etree.ElementPath Index Predicates

    LowCVSS 2.0No exploitEPSS 1%

    python software foundation · cpythonJul 28, 2026

  • Tarfile.extract() doesn't fully respect filter parameter

    LowCVSS 2.0No exploitEPSS 0%

    python · pythonJun 30, 2026

  • tarfile opened in streaming mode mishandles EOF

    HighCVSS 8.2No exploitEPSS 1%

    python software foundation · cpythonJun 23, 2026

  • CVE-2026-0864
    16Monitor

    Configuration Injection via Carriage Return (\r) in write() method

    MediumCVSS 4.1No exploitEPSS 0%

    python · pythonJun 23, 2026

  • tarfile extraction filter bypass allows escaping the destination directory

    HighCVSS 7.8No exploitEPSS 1%

    python software foundation · cpythonJun 23, 2026

  • CVE-2026-7774
    27Monitor

    tarfile.data_filter path traversal bypass allows writing outside the extraction directory

    MediumCVSS 6.9No exploitEPSS 1%

    python software foundation · cpythonJun 4, 2026

  • CVE-2026-3276
    25Monitor

    Potential DoS via quadratic complexity in unicodedata.normalize()

    MediumCVSS 6.3No exploitEPSS 1%

    python software foundation · cpythonJun 3, 2026