Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 113

Количество 1 113

redhat логотип

CVE-2026-4360

3 месяца назад

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2026-4360

3 месяца назад

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-4360

3 месяца назад

In the Tarfile.extract() function, the filter parameter is not passed ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-4224

6 месяцев назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-4224

6 месяцев назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-4224

6 месяцев назад

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-4224

6 месяцев назад

When an Expat parser with a registered ElementDeclHandler parses an in ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-3644

6 месяцев назад

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-3644

6 месяцев назад

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-3644

6 месяцев назад

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-3644

6 месяцев назад

The fix for CVE-2026-0672, which rejected control characters in http.c ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-3087

5 месяцев назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-3087

5 месяцев назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-3087

5 месяцев назад

If `shutil.unpack_archive()` is given a ZIP archive with an absolute W ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-15308

3 месяца назад

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-15308

3 месяца назад

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-15308

3 месяца назад

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-15308

3 месяца назад

The incremental HTML parser (html.parser.HTMLParser) allows for CPU de ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-0864

3 месяца назад

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-0864

3 месяца назад

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-4360

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-4360

In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.

CVSS3: 5.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-4360

In the Tarfile.extract() function, the filter parameter is not passed ...

CVSS3: 5.3
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-4224

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-4224

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 5.9
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-4224

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
debian логотип
CVE-2026-4224

When an Expat parser with a registered ElementDeclHandler parses an in ...

CVSS3: 7.5
1%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 5.4
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 7.5
1%
Низкий
6 месяцев назад
debian логотип
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.c ...

CVSS3: 7.5
1%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
debian логотип
CVE-2026-3087

If `shutil.unpack_archive()` is given a ZIP archive with an absolute W ...

CVSS3: 7.5
1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-15308

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

CVSS3: 7.5
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-15308

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

CVSS3: 7.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-15308

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

CVSS3: 7.5
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-15308

The incremental HTML parser (html.parser.HTMLParser) allows for CPU de ...

CVSS3: 7.5
1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-0864

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

CVSS3: 5.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-0864

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

CVSS3: 5.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу