Stan Ulbrych (https://github.com/StanFromIreland)
11 credited records · 11 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
23Monitor | CVE-2026-12345No exploit | Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directorypython software foundation · cpython · CWE-59 | Medium5.9 | — | — | Today |
33Monitor | CVE-2026-82049No exploit | tarfile extraction filters allow file modification and content disclosure via hard link to symlinkpython software foundation · cpython · CWE-59 | High8.4 | — | 0.2% | Sep 14, 2026 |
22Monitor | CVE-2026-87910No exploit | tarfile hardlink fallback ignores custom extraction filter rejection via Nonepython software foundation · cpython · CWE-22 | Medium5.7 | — | 0.5% | Sep 11, 2026 |
25Monitor | CVE-2026-19672No exploit | tarfile extraction filter bypass allows creation of directories outside the destinationpython software foundation · cpython · CWE-22 | Medium6.3 | — | 0.5% | Aug 19, 2026 |
24Monitor | CVE-2026-17084No exploit | stringprep.map_table_b2() deviates from RFC 3454 Table B.2python software foundation · cpython · CWE-436 | Medium6.0 | — | 0.7% | Aug 18, 2026 |
32Monitor | CVE-2026-11972No exploit | tarfile opened in streaming mode mishandles EOFpython software foundation · cpython · CWE-252 | High8.2 | — | 0.7% | Jun 23, 2026 |
31Monitor | CVE-2026-11940No exploit | tarfile extraction filter bypass allows escaping the destination directorypython software foundation · cpython · CWE-22 | High7.8 | — | 0.8% | Jun 23, 2026 |
32Monitor | CVE-2026-9669No exploit | bz2.BZ2Decompressor reuse after error can cause a stack buffer overflowpython software foundation · cpython · CWE-121 | High8.2 | — | 0.6% | Jun 8, 2026 |
27Monitor | CVE-2026-7774No exploit | tarfile.data_filter path traversal bypass allows writing outside the extraction directorypython software foundation · cpython · CWE-22 | Medium6.9 | — | 0.8% | Jun 4, 2026 |
25Monitor | CVE-2026-3276No exploit | Potential DoS via quadratic complexity in unicodedata.normalize()python software foundation · cpython · CWE-407 | Medium6.3 | — | 0.7% | Jun 3, 2026 |
25Monitor | CVE-2026-7210No exploit | The expat and elementtree parsers use insufficient entropy for XML hash-flooding protectionpython · python · CWE-331 | Medium6.3 | — | 1.4% | May 11, 2026 |
- CVE-2026-1234523Monitor
Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory
MediumCVSS 5.9No exploitpython software foundation · cpythonToday
- CVE-2026-8204933Monitor
tarfile extraction filters allow file modification and content disclosure via hard link to symlink
HighCVSS 8.4No exploitEPSS 0%python software foundation · cpythonSep 14, 2026
- CVE-2026-8791022Monitor
tarfile hardlink fallback ignores custom extraction filter rejection via None
MediumCVSS 5.7No exploitEPSS 1%python software foundation · cpythonSep 11, 2026
- CVE-2026-1967225Monitor
tarfile extraction filter bypass allows creation of directories outside the destination
MediumCVSS 6.3No exploitEPSS 1%python software foundation · cpythonAug 19, 2026
- CVE-2026-1708424Monitor
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
MediumCVSS 6.0No exploitEPSS 1%python software foundation · cpythonAug 18, 2026
- CVE-2026-1197232Monitor
tarfile opened in streaming mode mishandles EOF
HighCVSS 8.2No exploitEPSS 1%python software foundation · cpythonJun 23, 2026
- CVE-2026-1194031Monitor
tarfile extraction filter bypass allows escaping the destination directory
HighCVSS 7.8No exploitEPSS 1%python software foundation · cpythonJun 23, 2026
- CVE-2026-966932Monitor
bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow
HighCVSS 8.2No exploitEPSS 1%python software foundation · cpythonJun 8, 2026
- CVE-2026-777427Monitor
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
MediumCVSS 6.9No exploitEPSS 1%python software foundation · cpythonJun 4, 2026
- CVE-2026-327625Monitor
Potential DoS via quadratic complexity in unicodedata.normalize()
MediumCVSS 6.3No exploitEPSS 1%python software foundation · cpythonJun 3, 2026
- CVE-2026-721025Monitor
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
MediumCVSS 6.3No exploitEPSS 1%python · pythonMay 11, 2026