Petr Viktorin (https://github.com/encukou)
13 записей с упоминанием · 13 за 12 месяцев · 0 в CISA KEV
Имена — свободный текст из записей CNA; один человек может встречаться в разных написаниях. Напишите нам для исправления.
Записи с упоминанием
Исследователи| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
23Наблюдать | CVE-2026-12345Эксплойта нет | Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directorypython software foundation · cpython · CWE-59 | Средняя5,9 | — | — | Сегодня |
33Наблюдать | CVE-2026-82049Эксплойта нет | tarfile extraction filters allow file modification and content disclosure via hard link to symlinkpython software foundation · cpython · CWE-59 | Высокая8,4 | — | 0,2 % | 14 сент. 2026 г. |
22Наблюдать | CVE-2026-87910Эксплойта нет | tarfile hardlink fallback ignores custom extraction filter rejection via Nonepython software foundation · cpython · CWE-22 | Средняя5,7 | — | 0,5 % | 11 сент. 2026 г. |
8Наблюдать | CVE-2026-15310Эксплойта нет | zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limitspython software foundation · cpython · CWE-400 | Низкая2,1 | — | 0,5 % | 25 авг. 2026 г. |
25Наблюдать | CVE-2026-19672Эксплойта нет | tarfile extraction filter bypass allows creation of directories outside the destinationpython software foundation · cpython · CWE-22 | Средняя6,3 | — | 0,5 % | 19 авг. 2026 г. |
24Наблюдать | CVE-2026-17084Эксплойта нет | stringprep.map_table_b2() deviates from RFC 3454 Table B.2python software foundation · cpython · CWE-436 | Средняя6,0 | — | 0,7 % | 18 авг. 2026 г. |
8Наблюдать | CVE-2026-6879Эксплойта нет | Quadratic Behavior in xml.etree.ElementPath Index Predicatespython software foundation · cpython · CWE-407 | Низкая2,0 | — | 0,6 % | 28 июл. 2026 г. |
8Наблюдать | CVE-2026-4360Эксплойта нет | Tarfile.extract() doesn't fully respect filter parameterpython · python · CWE-281 | Низкая2,0 | — | 0,5 % | 30 июн. 2026 г. |
32Наблюдать | CVE-2026-11972Эксплойта нет | tarfile opened in streaming mode mishandles EOFpython software foundation · cpython · CWE-252 | Высокая8,2 | — | 0,7 % | 23 июн. 2026 г. |
16Наблюдать | CVE-2026-0864Эксплойта нет | Configuration Injection via Carriage Return (\r) in write() methodpython · python · CWE-74 | Средняя4,1 | — | 0,2 % | 23 июн. 2026 г. |
31Наблюдать | CVE-2026-11940Эксплойта нет | tarfile extraction filter bypass allows escaping the destination directorypython software foundation · cpython · CWE-22 | Высокая7,8 | — | 0,8 % | 23 июн. 2026 г. |
27Наблюдать | CVE-2026-7774Эксплойта нет | tarfile.data_filter path traversal bypass allows writing outside the extraction directorypython software foundation · cpython · CWE-22 | Средняя6,9 | — | 0,8 % | 4 июн. 2026 г. |
25Наблюдать | CVE-2026-3276Эксплойта нет | Potential DoS via quadratic complexity in unicodedata.normalize()python software foundation · cpython · CWE-407 | Средняя6,3 | — | 0,7 % | 3 июн. 2026 г. |
- CVE-2026-1234523Наблюдать
Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory
СредняяCVSS 5,9Эксплойта нетpython software foundation · cpythonСегодня
- CVE-2026-8204933Наблюдать
tarfile extraction filters allow file modification and content disclosure via hard link to symlink
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %python software foundation · cpython14 сент. 2026 г.
- CVE-2026-8791022Наблюдать
tarfile hardlink fallback ignores custom extraction filter rejection via None
СредняяCVSS 5,7Эксплойта нетEPSS 1 %python software foundation · cpython11 сент. 2026 г.
- CVE-2026-153108Наблюдать
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %python software foundation · cpython25 авг. 2026 г.
- CVE-2026-1967225Наблюдать
tarfile extraction filter bypass allows creation of directories outside the destination
СредняяCVSS 6,3Эксплойта нетEPSS 1 %python software foundation · cpython19 авг. 2026 г.
- CVE-2026-1708424Наблюдать
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
СредняяCVSS 6,0Эксплойта нетEPSS 1 %python software foundation · cpython18 авг. 2026 г.
- CVE-2026-68798Наблюдать
Quadratic Behavior in xml.etree.ElementPath Index Predicates
НизкаяCVSS 2,0Эксплойта нетEPSS 1 %python software foundation · cpython28 июл. 2026 г.
- CVE-2026-43608Наблюдать
Tarfile.extract() doesn't fully respect filter parameter
НизкаяCVSS 2,0Эксплойта нетEPSS 0 %python · python30 июн. 2026 г.
- CVE-2026-1197232Наблюдать
tarfile opened in streaming mode mishandles EOF
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %python software foundation · cpython23 июн. 2026 г.
- CVE-2026-086416Наблюдать
Configuration Injection via Carriage Return (\r) in write() method
СредняяCVSS 4,1Эксплойта нетEPSS 0 %python · python23 июн. 2026 г.
- CVE-2026-1194031Наблюдать
tarfile extraction filter bypass allows escaping the destination directory
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %python software foundation · cpython23 июн. 2026 г.
- CVE-2026-777427Наблюдать
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
СредняяCVSS 6,9Эксплойта нетEPSS 1 %python software foundation · cpython4 июн. 2026 г.
- CVE-2026-327625Наблюдать
Potential DoS via quadratic complexity in unicodedata.normalize()
СредняяCVSS 6,3Эксплойта нетEPSS 1 %python software foundation · cpython3 июн. 2026 г.