pylonsproject records
4 published records for vendor pylonsproject.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 75%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-208 Observable Timing Discrepancy1
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2017-18361No exploit | In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of servipylonsproject · colander · CWE-835 | High7.5 | — | 1.8% | Feb 1, 2019 |
24Monitor | CVE-2024-42353No exploit | WebOb's location header normalization during redirect leads to open redirectpylonsproject · webob · CWE-601 | Medium6.1 | — | 0.6% | Aug 14, 2024 |
24Monitor | CVE-2026-44889No exploit | WebOb: Location header normalization during redirect leads to open redirectpylonsproject · webob · CWE-601 | Medium6.1 | — | 0.3% | Jun 22, 2026 |
21Monitor | CVE-2014-125056No exploit | Pylons horus services.py timing discrepancypylonsproject · horus · CWE-208 | Medium5.3 | — | 0.7% | Jan 7, 2023 |
- CVE-2017-1836131Monitor
In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of servi
HighCVSS 7.5No exploitEPSS 2%pylonsproject · colanderFeb 1, 2019
- CVE-2024-4235324Monitor
WebOb's location header normalization during redirect leads to open redirect
MediumCVSS 6.1No exploitEPSS 1%pylonsproject · webobAug 14, 2024
- CVE-2026-4488924Monitor
WebOb: Location header normalization during redirect leads to open redirect
MediumCVSS 6.1No exploitEPSS 0%pylonsproject · webobJun 22, 2026
- CVE-2014-12505621Monitor
Pylons horus services.py timing discrepancy
MediumCVSS 5.3No exploitEPSS 1%pylonsproject · horusJan 7, 2023