Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 998

Количество 998

ubuntu логотип

CVE-2026-4360

около 1 месяца назад

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-4360

около 1 месяца назад

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2026-4360

около 1 месяца назад

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-4360

около 1 месяца назад

In the Tarfile.extract() function, the filter parameter is not passed ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-4224

5 месяцев назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-4224

5 месяцев назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-4224

5 месяцев назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-4224

5 месяцев назад

When an Expat parser with a registered ElementDeclHandler parses an in ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-3644

5 месяцев назад

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-3644

5 месяцев назад

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-3644

5 месяцев назад

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-3644

5 месяцев назад

The fix for CVE-2026-0672, which rejected control characters in http.c ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-3087

3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-3087

3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-3087

3 месяца назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute W ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-15308

22 дня назад

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-15308

22 дня назад

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-15308

22 дня назад

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-15308

22 дня назад

The incremental HTML parser (html.parser.HTMLParser) allows for CPU de ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-6075

9 месяцев назад

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-4360

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-4360

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-4360

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-4360

In the Tarfile.extract() function, the filter parameter is not passed ...

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-4224

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-4224

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 5.9
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-4224

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
debian логотип
CVE-2026-4224

When an Expat parser with a registered ElementDeclHandler parses an in ...

CVSS3: 7.5
1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 7.5
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 5.4
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 7.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.c ...

CVSS3: 7.5
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute W ...

CVSS3: 7.5
1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-15308

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

CVSS3: 7.5
1%
Низкий
22 дня назад
redhat логотип
CVE-2026-15308

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

CVSS3: 7.5
1%
Низкий
22 дня назад
nvd логотип
CVE-2026-15308

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

CVSS3: 7.5
1%
Низкий
22 дня назад
debian логотип
CVE-2026-15308

The incremental HTML parser (html.parser.HTMLParser) allows for CPU de ...

CVSS3: 7.5
1%
Низкий
22 дня назад
ubuntu логотип
CVE-2025-6075

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVSS3: 5.5
0%
Низкий
9 месяцев назад

Уязвимостей на страницу