Количество 26
Количество 26
CVE-2026-6019
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
CVE-2026-6019
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
CVE-2026-6019
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
CVE-2026-6019
BaseCookie.js_output() does not neutralize embedded characters
CVE-2026-6019
http.cookies.Morsel.js_output() returns an inline <script> snippet and ...
ROS-20260728-80-0020
Уязвимость python-PyPDF2
GHSA-2755-2mm4-rm5c
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
BDU:2026-13663
Уязвимость метода http.cookies.Morsel.js_output() интерпретатора языка программирования Python (CPython), позволяющая нарушителю выполнить произвольный код
SUSE-SU-2026:3648-1
Security update for python311
RLSA-2026:28581
Important: python3.14 security, bug fix, and enhancement update
RLSA-2026:28247
Important: python3.14 security, bug fix, and enhancement update
ELSA-2026-28581
ELSA-2026-28581: python3.14 security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-28247
ELSA-2026-28247: python3.14 security, bug fix, and enhancement update (IMPORTANT)
SUSE-SU-2026:3132-1
Security update for python311
SUSE-SU-2026:3104-1
Security update for python311
SUSE-SU-2026:2055-1
Security update for python312
SUSE-SU-2026:2464-1
Security update for python313
SUSE-SU-2026:1947-1
Security update for python310
SUSE-SU-2026:1937-1
Security update for python3
openSUSE-SU-2026:21459-1
Security update for python313, python3
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. | CVSS3: 6.1 | 0% Низкий | 5 месяцев назад | |
CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. | CVSS3: 6.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. | CVSS3: 6.1 | 0% Низкий | 5 месяцев назад | |
CVE-2026-6019 BaseCookie.js_output() does not neutralize embedded characters | 0% Низкий | 3 месяца назад | ||
CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline <script> snippet and ... | CVSS3: 6.1 | 0% Низкий | 5 месяцев назад | |
ROS-20260728-80-0020 Уязвимость python-PyPDF2 | CVSS3: 3.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-2755-2mm4-rm5c http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. | CVSS3: 6.1 | 0% Низкий | 5 месяцев назад | |
BDU:2026-13663 Уязвимость метода http.cookies.Morsel.js_output() интерпретатора языка программирования Python (CPython), позволяющая нарушителю выполнить произвольный код | CVSS3: 6.1 | 0% Низкий | 5 месяцев назад | |
SUSE-SU-2026:3648-1 Security update for python311 | 26 дней назад | |||
RLSA-2026:28581 Important: python3.14 security, bug fix, and enhancement update | 3 месяца назад | |||
RLSA-2026:28247 Important: python3.14 security, bug fix, and enhancement update | 3 месяца назад | |||
ELSA-2026-28581 ELSA-2026-28581: python3.14 security, bug fix, and enhancement update (IMPORTANT) | 2 месяца назад | |||
ELSA-2026-28247 ELSA-2026-28247: python3.14 security, bug fix, and enhancement update (IMPORTANT) | 3 месяца назад | |||
SUSE-SU-2026:3132-1 Security update for python311 | около 2 месяцев назад | |||
SUSE-SU-2026:3104-1 Security update for python311 | около 2 месяцев назад | |||
SUSE-SU-2026:2055-1 Security update for python312 | 4 месяца назад | |||
SUSE-SU-2026:2464-1 Security update for python313 | 3 месяца назад | |||
SUSE-SU-2026:1947-1 Security update for python310 | 4 месяца назад | |||
SUSE-SU-2026:1937-1 Security update for python3 | 4 месяца назад | |||
openSUSE-SU-2026:21459-1 Security update for python313, python3 | около 2 месяцев назад |
Уязвимостей на страницу