← All credits
Seth Larson (https://github.com/sethmlarson)
12 vulnerability records and advisories credit this contributor.
CVE-2026-19553
SSLContext.wrap_bio() missing validation of server_hostname parameter
CVE-2026-19445
Use-after-free of a server-side SSLContext when sni_callback switches contexts
CVE-2026-17084
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
CVE-2026-15308
Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
CVE-2026-0864
Configuration Injection via Carriage Return (\r) in write() method
CVE-2026-18503
Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()
CVE-2026-7774
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
CVE-2026-4360
Tarfile.extract() doesn't fully respect filter parameter
CVE-2026-3298
Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
CVE-2026-3276
Potential DoS via quadratic complexity in unicodedata.normalize()