Petr Viktorin (https://github.com/encukou)
13 kredili kayıt · son 12 ayda 13 · 0 tanesi CISA KEV’de
Adlar CNA kayıtlarındaki serbest metindir; aynı kişi farklı yazımlarla ayrı görünebilir. Düzeltme için bize yazın.
Kredili kayıtlar
Araştırmacılar| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
23İzleyin | CVE-2026-12345İstismar yok | Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directorypython software foundation · cpython · CWE-59 | Orta5,9 | — | — | Bugün |
33İzleyin | CVE-2026-82049İstismar yok | tarfile extraction filters allow file modification and content disclosure via hard link to symlinkpython software foundation · cpython · CWE-59 | Yüksek8,4 | — | %0,2 | 14 Eyl 2026 |
22İzleyin | CVE-2026-87910İstismar yok | tarfile hardlink fallback ignores custom extraction filter rejection via Nonepython software foundation · cpython · CWE-22 | Orta5,7 | — | %0,5 | 11 Eyl 2026 |
8İzleyin | CVE-2026-15310İstismar yok | zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limitspython software foundation · cpython · CWE-400 | Düşük2,1 | — | %0,5 | 25 Ağu 2026 |
25İzleyin | CVE-2026-19672İstismar yok | tarfile extraction filter bypass allows creation of directories outside the destinationpython software foundation · cpython · CWE-22 | Orta6,3 | — | %0,5 | 19 Ağu 2026 |
24İzleyin | CVE-2026-17084İstismar yok | stringprep.map_table_b2() deviates from RFC 3454 Table B.2python software foundation · cpython · CWE-436 | Orta6,0 | — | %0,7 | 18 Ağu 2026 |
8İzleyin | CVE-2026-6879İstismar yok | Quadratic Behavior in xml.etree.ElementPath Index Predicatespython software foundation · cpython · CWE-407 | Düşük2,0 | — | %0,6 | 28 Tem 2026 |
8İzleyin | CVE-2026-4360İstismar yok | Tarfile.extract() doesn't fully respect filter parameterpython · python · CWE-281 | Düşük2,0 | — | %0,5 | 30 Haz 2026 |
32İzleyin | CVE-2026-11972İstismar yok | tarfile opened in streaming mode mishandles EOFpython software foundation · cpython · CWE-252 | Yüksek8,2 | — | %0,7 | 23 Haz 2026 |
16İzleyin | CVE-2026-0864İstismar yok | Configuration Injection via Carriage Return (\r) in write() methodpython · python · CWE-74 | Orta4,1 | — | %0,2 | 23 Haz 2026 |
31İzleyin | CVE-2026-11940İstismar yok | tarfile extraction filter bypass allows escaping the destination directorypython software foundation · cpython · CWE-22 | Yüksek7,8 | — | %0,8 | 23 Haz 2026 |
27İzleyin | CVE-2026-7774İstismar yok | tarfile.data_filter path traversal bypass allows writing outside the extraction directorypython software foundation · cpython · CWE-22 | Orta6,9 | — | %0,8 | 4 Haz 2026 |
25İzleyin | CVE-2026-3276İstismar yok | Potential DoS via quadratic complexity in unicodedata.normalize()python software foundation · cpython · CWE-407 | Orta6,3 | — | %0,7 | 3 Haz 2026 |
- CVE-2026-1234523İzleyin
Race condition in tempfile.TemporaryDirectory cleanup allows deleting files outside the temporary directory
OrtaCVSS 5,9İstismar yokpython software foundation · cpythonBugün
- CVE-2026-8204933İzleyin
tarfile extraction filters allow file modification and content disclosure via hard link to symlink
YüksekCVSS 8,4İstismar yokEPSS %0python software foundation · cpython14 Eyl 2026
- CVE-2026-8791022İzleyin
tarfile hardlink fallback ignores custom extraction filter rejection via None
OrtaCVSS 5,7İstismar yokEPSS %1python software foundation · cpython11 Eyl 2026
- CVE-2026-153108İzleyin
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
DüşükCVSS 2,1İstismar yokEPSS %1python software foundation · cpython25 Ağu 2026
- CVE-2026-1967225İzleyin
tarfile extraction filter bypass allows creation of directories outside the destination
OrtaCVSS 6,3İstismar yokEPSS %1python software foundation · cpython19 Ağu 2026
- CVE-2026-1708424İzleyin
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
OrtaCVSS 6,0İstismar yokEPSS %1python software foundation · cpython18 Ağu 2026
- CVE-2026-68798İzleyin
Quadratic Behavior in xml.etree.ElementPath Index Predicates
DüşükCVSS 2,0İstismar yokEPSS %1python software foundation · cpython28 Tem 2026
- CVE-2026-43608İzleyin
Tarfile.extract() doesn't fully respect filter parameter
DüşükCVSS 2,0İstismar yokEPSS %0python · python30 Haz 2026
- CVE-2026-1197232İzleyin
tarfile opened in streaming mode mishandles EOF
YüksekCVSS 8,2İstismar yokEPSS %1python software foundation · cpython23 Haz 2026
- CVE-2026-086416İzleyin
Configuration Injection via Carriage Return (\r) in write() method
OrtaCVSS 4,1İstismar yokEPSS %0python · python23 Haz 2026
- CVE-2026-1194031İzleyin
tarfile extraction filter bypass allows escaping the destination directory
YüksekCVSS 7,8İstismar yokEPSS %1python software foundation · cpython23 Haz 2026
- CVE-2026-777427İzleyin
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
OrtaCVSS 6,9İstismar yokEPSS %1python software foundation · cpython4 Haz 2026
- CVE-2026-327625İzleyin
Potential DoS via quadratic complexity in unicodedata.normalize()
OrtaCVSS 6,3İstismar yokEPSS %1python software foundation · cpython3 Haz 2026