<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:36:06.433333+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:4766</id>
    <title>ALSA-2024:4766 — Low: python3 security update</title>
    <updated>2026-10-03T02:36:06.490094+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: python3.11, AlmaLinux:9: python3.11-debug, AlmaLinux:9: python3.11-devel, AlmaLinux:9: python3.11-idle, AlmaLinux:9: python3.11-libs, AlmaLinux:9: python3.11-test, AlmaLinux:9: python3.11-tkinter</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* python: incorrect IPv4 and IPv6 private ranges (CVE-2024-4032)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:4766"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-05196</id>
    <title>bdu:2024-05196</title>
    <updated>2026-10-03T02:36:06.490171+00:00</updated>
    <content>bdu:2024-05196</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-05196"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-4032</id>
    <title>BELL-CVE-2024-4032</title>
    <updated>2026-10-03T02:36:06.490189+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:stream: python3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-4032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-libpython-2024-4032</id>
    <title>BIT-libpython-2024-4032 — Incorrect IPv4 and IPv6 private ranges</title>
    <updated>2026-10-03T02:36:06.490213+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: libpython</p>
<p>The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.</p>
<p>CPython 3.12.4 and 3.13.0 contain updated information from these registries and thus have the intended behavior.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-libpython-2024-4032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0540</id>
    <title>certfr-2024-avi-0540 — De multiples vulnérabilités ont été découvertes dans Python. Elles permettent à un attaquant de provoquer un contournem…</title>
    <updated>2026-10-03T02:36:06.490239+00:00</updated>
    <content>certfr-2024-avi-0540</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0540"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cq39979</id>
    <title>Withdrawn: CLEANSTART-2026-CQ39979 — Security fixes in cassandra 5.0.6-r2</title>
    <updated>2026-10-03T02:36:06.490255+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cassandra</p>
<p>Package cassandra version 5.0.6-r2 fixes 26 vulnerabilities: ghsa-72hv-8253-57qq, ghsa-pr98-23f8-jwxv, ghsa-25qh-j22f-pwp8, ghsa-6v67-2wr5-gvf4, ghsa-qqpg-mvqg-649v...</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cq39979"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258651</id>
    <title>EUVD-2026-258651</title>
    <updated>2026-10-03T02:36:06.490274+00:00</updated>
    <content>EUVD-2026-258651</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258651"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-4032</id>
    <title>fkie_cve-2024-4032</title>
    <updated>2026-10-03T02:36:06.490285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.</p>
<p>CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-4032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mh6q-v4mp-2cc7</id>
    <title>GHSA-mh6q-v4mp-2cc7</title>
    <updated>2026-10-03T02:36:06.490310+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.</p>
<p>CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mh6q-v4mp-2cc7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-4032</id>
    <title>gsd-2024-4032</title>
    <updated>2026-10-03T02:36:06.490327+00:00</updated>
    <content>gsd-2024-4032</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-4032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-4032</id>
    <title>msrc_CVE-2024-4032 — Incorrect IPv4 and IPv6 private ranges</title>
    <updated>2026-10-03T02:36:06.490338+00:00</updated>
    <content>msrc_CVE-2024-4032</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-4032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1940</id>
    <title>OESA-2024-1940 — python3 security update</title>
    <updated>2026-10-03T02:36:06.490352+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: python3</p>
<p>Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.

Security Fix(es):

A defect was discovered in the Python “ssl” module where there is a memory
race condition with the ssl.SSLContext methods “cert_store_stats()” and
“get_ca_certs()”. The race condition can be triggered if the methods are
called at the same time as certificates are loaded into the SSLContext,
such as during the TLS handshake with a certificate directory configured.
This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.(CVE-2024-0397)

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.

CPython 3.12.4 and 3.13.0a6 contain updated information from…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1940"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14078-1</id>
    <title>openSUSE-SU-2024:14078-1 — python38-3.8.19-4.1 on GA media</title>
    <updated>2026-10-03T02:36:06.490384+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python38-3.8.19-4.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14078-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:5962</id>
    <title>RHSA-2024:5962 — Red Hat Security Advisory: python39:3.9 and python39-devel:3.9 security update</title>
    <updated>2026-10-03T02:36:06.490400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python: incorrect IPv4 and IPv6 private ranges pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools cpython: python: email module doesn't properly quotes newlines in email headers, allowing header injection python: cpython: Iterating over a malicious ZIP file may lead to Denial of Service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:5962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2024-4029</id>
    <title>SUSE-EL-9-CLIENT-TOOLS-2024-4029 — Security update for SUSE Manager Salt Bundle</title>
    <updated>2026-10-03T02:36:06.490421+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for SUSE Manager Salt Bundle</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2024-4029"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4032</id>
    <title>UBUNTU-CVE-2024-4032</title>
    <updated>2026-10-03T02:36:06.490439+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:20.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.9, Ubuntu:22.04:LTS: python3.10, Ubuntu:Pro:22.04:LTS: python3.11 and 1 more</p>
<p>The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4032"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1396</id>
    <title>WID-SEC-W-2024-1396 — Python: Mehrere Schwachstellen ermöglichen Manipulation von Dateien und Umgehung von Sicherheitsmaßnahmen</title>
    <updated>2026-10-03T02:36:06.490477+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Python ausnutzen, um Dateien zu manipulieren und Sicherheitsmaßnahmen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1396"/>
  </entry>
</feed>
