Skip to content
Noroxi

Stan Ulbrych (https://github.com/StanFromIreland)

11 credited records · 11 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory

    MediumCVSS 5.9No exploit

    python software foundation · cpythonToday

  • tarfile extraction filters allow file modification and content disclosure via hard link to symlink

    HighCVSS 8.4No exploitEPSS 0%

    python software foundation · cpythonSep 14, 2026

  • tarfile hardlink fallback ignores custom extraction filter rejection via None

    MediumCVSS 5.7No exploitEPSS 1%

    python software foundation · cpythonSep 11, 2026

  • tarfile extraction filter bypass allows creation of directories outside the destination

    MediumCVSS 6.3No exploitEPSS 1%

    python software foundation · cpythonAug 19, 2026

  • stringprep.map_table_b2() deviates from RFC 3454 Table B.2

    MediumCVSS 6.0No exploitEPSS 1%

    python software foundation · cpythonAug 18, 2026

  • tarfile opened in streaming mode mishandles EOF

    HighCVSS 8.2No exploitEPSS 1%

    python software foundation · cpythonJun 23, 2026

  • tarfile extraction filter bypass allows escaping the destination directory

    HighCVSS 7.8No exploitEPSS 1%

    python software foundation · cpythonJun 23, 2026

  • CVE-2026-9669
    32Monitor

    bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow

    HighCVSS 8.2No exploitEPSS 1%

    python software foundation · cpythonJun 8, 2026

  • CVE-2026-7774
    27Monitor

    tarfile.data_filter path traversal bypass allows writing outside the extraction directory

    MediumCVSS 6.9No exploitEPSS 1%

    python software foundation · cpythonJun 4, 2026

  • CVE-2026-3276
    25Monitor

    Potential DoS via quadratic complexity in unicodedata.normalize()

    MediumCVSS 6.3No exploitEPSS 1%

    python software foundation · cpythonJun 3, 2026

  • CVE-2026-7210
    25Monitor

    The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection

    MediumCVSS 6.3No exploitEPSS 1%

    python · pythonMay 11, 2026