Python — высокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 3.13.15 | 3.13.15 | ||
| 3.13.14 | 3.13.14 | ||
| 3.13.13 | 3.13.13 | ||
| 3.13.12 | 3.13.12 | ||
| 3.13.11 | 3.13.11 | ||
| 3.13.10 | 3.13.10 | ||
| 3.13.9 | 3.13.9 | ||
| 3.13.8 | 3.13.8 | ||
| 3.13.7 | 3.13.7 | ||
| 3.13.6 | 3.13.6 |
Показывать по
Количество 1 113
GHSA-h46w-ffvp-4pw5
When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.
GHSA-vf33-88pf-hwp3
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().
CVE-2025-13462
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.
CVE-2025-13462
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.
CVE-2025-13462
The "tarfile" module would still apply normalization of AREGTYPE (\x00 ...
CVE-2025-13462
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.
GHSA-9qpv-486p-2v4h
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.
ELSA-2026-2713
ELSA-2026-2713: python3 security update (MODERATE)
SUSE-SU-2026:0802-1
Security update for python
SUSE-SU-2026:0774-1
Security update for python
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-h46w-ffvp-4pw5 When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
GHSA-vf33-88pf-hwp3 The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output(). | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
CVE-2025-13462 The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations. | CVSS3: 3.3 | 0% Низкий | 7 месяцев назад | |
CVE-2025-13462 The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations. | CVSS3: 2.5 | 0% Низкий | 7 месяцев назад | |
CVE-2025-13462 The "tarfile" module would still apply normalization of AREGTYPE (\x00 ... | CVSS3: 3.3 | 0% Низкий | 7 месяцев назад | |
CVE-2025-13462 The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations. | CVSS3: 3.3 | 0% Низкий | 7 месяцев назад | |
GHSA-9qpv-486p-2v4h The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations. | CVSS3: 9.8 | 0% Низкий | 7 месяцев назад | |
ELSA-2026-2713 ELSA-2026-2713: python3 security update (MODERATE) | 1% Низкий | 7 месяцев назад | ||
SUSE-SU-2026:0802-1 Security update for python | 2% Низкий | 7 месяцев назад | ||
SUSE-SU-2026:0774-1 Security update for python | 2% Низкий | 7 месяцев назад |
Уязвимостей на страницу