Python — высокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.
Релизный цикл, информация об уязвимостях
График релизов
Количество 990
CVE-2026-15308
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
GHSA-7qj2-q5c8-cxx5
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
CVE-2026-15308
The incremental HTML parser (html.parser.HTMLParser) allows for CPU de ...
CVE-2026-15308
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
CVE-2026-15308
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
GHSA-gf2w-jqmq-fcm8
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.
CVE-2026-4360
In the Tarfile.extract() function, the filter parameter is not passed ...
CVE-2026-4360
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.
CVE-2026-4360
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.
RLSA-2023:2860
Moderate: python27:2.7 security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2026-15308 The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data. | CVSS3: 7.5 | 1% Низкий | 21 день назад | |
GHSA-7qj2-q5c8-cxx5 The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data. | CVSS3: 7.5 | 1% Низкий | 21 день назад | |
CVE-2026-15308 The incremental HTML parser (html.parser.HTMLParser) allows for CPU de ... | CVSS3: 7.5 | 1% Низкий | 21 день назад | |
CVE-2026-15308 The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data. | CVSS3: 7.5 | 1% Низкий | 21 день назад | |
CVE-2026-15308 The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data. | CVSS3: 7.5 | 1% Низкий | 21 день назад | |
GHSA-gf2w-jqmq-fcm8 In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function. | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-4360 In the Tarfile.extract() function, the filter parameter is not passed ... | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-4360 In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function. | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-4360 In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function. | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
RLSA-2023:2860 Moderate: python27:2.7 security update | 2% Низкий | около 1 месяца назад |
Уязвимостей на страницу