Skip to content
Noroxi

Seth Larson (https://github.com/sethmlarson)

10 credited records · 10 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • stringprep.map_table_b2() deviates from RFC 3454 Table B.2

    MediumCVSS 6.0No exploitEPSS 1%

    python software foundation · cpythonAug 18, 2026

  • Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()

    LowCVSS 2.4No exploitEPSS 0%

    python software foundation · cpythonAug 10, 2026

  • Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations

    HighCVSS 8.7No exploitEPSS 1%

    python · pythonJul 9, 2026

  • Tarfile.extract() doesn't fully respect filter parameter

    LowCVSS 2.0No exploitEPSS 0%

    python · pythonJun 30, 2026

  • CVE-2026-0864
    16Monitor

    Configuration Injection via Carriage Return (\r) in write() method

    MediumCVSS 4.1No exploitEPSS 0%

    python · pythonJun 23, 2026

  • CVE-2026-7774
    27Monitor

    tarfile.data_filter path traversal bypass allows writing outside the extraction directory

    MediumCVSS 6.9No exploitEPSS 1%

    python software foundation · cpythonJun 4, 2026

  • CVE-2026-3276
    25Monitor

    Potential DoS via quadratic complexity in unicodedata.normalize()

    MediumCVSS 6.3No exploitEPSS 1%

    python software foundation · cpythonJun 3, 2026

  • CVE-2026-3087
    24Monitor

    shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs

    MediumCVSS 6.0No exploitEPSS 1%

    python · pythonApr 27, 2026

  • BaseCookie.js_output() does not neutralize embedded characters

    LowCVSS 2.1No exploitEPSS 1%

    python · pythonApr 22, 2026

  • CVE-2026-3298
    35Monitor

    Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes

    HighCVSS 8.8No exploitEPSS 1%

    python software foundation · cpythonApr 21, 2026