Seth Larson (https://github.com/sethmlarson)
10 credited records · 10 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
24Monitor | CVE-2026-17084No exploit | stringprep.map_table_b2() deviates from RFC 3454 Table B.2python software foundation · cpython · CWE-436 | Medium6.0 | — | 0.7% | Aug 18, 2026 |
9Monitor | CVE-2026-18503No exploit | Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()python software foundation · cpython · CWE-1176 | Low2.4 | — | 0.1% | Aug 10, 2026 |
34Monitor | CVE-2026-15308No exploit | Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarationspython · python · CWE-400 | High8.7 | — | 0.6% | Jul 9, 2026 |
8Monitor | CVE-2026-4360No exploit | Tarfile.extract() doesn't fully respect filter parameterpython · python · CWE-281 | Low2.0 | — | 0.5% | Jun 30, 2026 |
16Monitor | CVE-2026-0864No exploit | Configuration Injection via Carriage Return (\r) in write() methodpython · python · CWE-74 | Medium4.1 | — | 0.2% | Jun 23, 2026 |
27Monitor | CVE-2026-7774No exploit | tarfile.data_filter path traversal bypass allows writing outside the extraction directorypython software foundation · cpython · CWE-22 | Medium6.9 | — | 0.8% | Jun 4, 2026 |
25Monitor | CVE-2026-3276No exploit | Potential DoS via quadratic complexity in unicodedata.normalize()python software foundation · cpython · CWE-407 | Medium6.3 | — | 0.7% | Jun 3, 2026 |
24Monitor | CVE-2026-3087No exploit | shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPspython · python · CWE-22 | Medium6.0 | — | 0.7% | Apr 27, 2026 |
8Monitor | CVE-2026-6019No exploit | BaseCookie.js_output() does not neutralize embedded characterspython · python · CWE-150 | Low2.1 | — | 0.6% | Apr 22, 2026 |
35Monitor | CVE-2026-3298No exploit | Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytespython software foundation · cpython · CWE-787 | High8.8 | — | 0.6% | Apr 21, 2026 |
- CVE-2026-1708424Monitor
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
MediumCVSS 6.0No exploitEPSS 1%python software foundation · cpythonAug 18, 2026
- CVE-2026-185039Monitor
Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()
LowCVSS 2.4No exploitEPSS 0%python software foundation · cpythonAug 10, 2026
- CVE-2026-1530834Monitor
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
HighCVSS 8.7No exploitEPSS 1%python · pythonJul 9, 2026
- CVE-2026-43608Monitor
Tarfile.extract() doesn't fully respect filter parameter
LowCVSS 2.0No exploitEPSS 0%python · pythonJun 30, 2026
- CVE-2026-086416Monitor
Configuration Injection via Carriage Return (\r) in write() method
MediumCVSS 4.1No exploitEPSS 0%python · pythonJun 23, 2026
- CVE-2026-777427Monitor
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
MediumCVSS 6.9No exploitEPSS 1%python software foundation · cpythonJun 4, 2026
- CVE-2026-327625Monitor
Potential DoS via quadratic complexity in unicodedata.normalize()
MediumCVSS 6.3No exploitEPSS 1%python software foundation · cpythonJun 3, 2026
- CVE-2026-308724Monitor
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
MediumCVSS 6.0No exploitEPSS 1%python · pythonApr 27, 2026
- CVE-2026-60198Monitor
BaseCookie.js_output() does not neutralize embedded characters
LowCVSS 2.1No exploitEPSS 1%python · pythonApr 22, 2026
- CVE-2026-329835Monitor
Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
HighCVSS 8.8No exploitEPSS 1%python software foundation · cpythonApr 21, 2026