<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T15:29:26.542573+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2019:3335</id>
    <title>ALSA-2019:3335 — Moderate: python27:2.7 security and bug fix update</title>
    <updated>2026-10-02T15:29:27.854547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python-psycopg2-doc, AlmaLinux:8: python2-Cython, AlmaLinux:8: python2-PyMySQL, AlmaLinux:8: python2-attrs, AlmaLinux:8: python2-chardet, AlmaLinux:8: python2-coverage, AlmaLinux:8: python2-dns, AlmaLinux:8: python2-docs, AlmaLinux:8: python2-docs-info, AlmaLinux:8: python2-docutils and 17 more</p>
<p>Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing.</p>
<p>Security Fix(es):</p>
<p>* numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code execution (CVE-2019-6446)</p>
<p>* python: CRLF injection via the query part of the url passed to urlopen() (CVE-2019-9740)</p>
<p>* python: CRLF injection via the path part of the url passed to urlopen() (CVE-2019-9947)</p>
<p>* python: Undocumented local_file protocol allows remote attackers to bypass protection mechanisms (CVE-2019-9948)</p>
<p>* python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service (CVE-2019-11236)</p>
<p>* python-urllib3: Certification mishandle when error should be thrown (CVE-2019-11324)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2019:3335"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-02105</id>
    <title>bdu:2019-02105</title>
    <updated>2026-10-02T15:29:27.854655+00:00</updated>
    <content>bdu:2019-02105</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-02105"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2019-11324</id>
    <title>Withdrawn: BELL-CVE-2019-11324 — CVE-2019-11324 does not affect BellSoft software</title>
    <updated>2026-10-02T15:29:27.854673+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2019-11324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2019-11324</id>
    <title>BREW-ansible-CVE-2019-11324 — Improper Certificate Validation in urllib3</title>
    <updated>2026-10-02T15:29:27.854689+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: ansible</p>
<p>The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the `ssl_context`, `ca_certs`, or `ca_certs_dir` argument.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-ansible-cve-2019-11324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-267</id>
    <title>certfr-2022-avi-267 — De multiples vulnérabilités ont été découvertes dans Juniper Networks
Junos Space. Elles permettent à un attaquant de p…</title>
    <updated>2026-10-02T15:29:27.854711+00:00</updated>
    <content>certfr-2022-avi-267</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-54331</id>
    <title>EUVD-2026-54331</title>
    <updated>2026-10-02T15:29:27.854726+00:00</updated>
    <content>EUVD-2026-54331</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-54331"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-11324</id>
    <title>fkie_cve-2019-11324</title>
    <updated>2026-10-02T15:29:27.854737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-11324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mh33-7rrq-662w</id>
    <title>GHSA-mh33-7rrq-662w — Improper Certificate Validation in urllib3</title>
    <updated>2026-10-02T15:29:27.854757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: urllib3</p>
<p>The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the `ssl_context`, `ca_certs`, or `ca_certs_dir` argument.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mh33-7rrq-662w"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-11324</id>
    <title>gsd-2019-11324</title>
    <updated>2026-10-02T15:29:27.854777+00:00</updated>
    <content>gsd-2019-11324</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-11324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2019-11324</id>
    <title>msrc_CVE-2019-11324 — The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is diffe…</title>
    <updated>2026-10-02T15:29:27.854788+00:00</updated>
    <content>msrc_CVE-2019-11324</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2019-11324"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2019:2131-1</id>
    <title>openSUSE-SU-2019:2131-1 — Security update for python-urllib3</title>
    <updated>2026-10-02T15:29:27.854805+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-urllib3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2019:2131-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2019-133</id>
    <title>PYSEC-2019-133</title>
    <updated>2026-10-02T15:29:27.854821+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: urllib3</p>
<p>The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2019-133"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2020:2785</id>
    <title>RHBA-2020:2785 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.4.11 packages update</title>
    <updated>2026-10-02T15:29:27.854840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service python-urllib3: Certification mishandle when error should be thrown</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2020:2785"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2019:2300-1</id>
    <title>SUSE-SU-2019:2300-1 — Security update for python-urllib3</title>
    <updated>2026-10-02T15:29:27.854858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-urllib3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2019:2300-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-11324</id>
    <title>UBUNTU-CVE-2019-11324</title>
    <updated>2026-10-02T15:29:27.854873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: python-urllib3</p>
<p>The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-11324"/>
  </entry>
</feed>
