<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T23:51:45.637081+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:10779</id>
    <title>ALSA-2024:10779 — Moderate: python3:3.6.8 security update</title>
    <updated>2026-10-02T23:51:45.705519+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: platform-python, AlmaLinux:8: platform-python-debug, AlmaLinux:8: platform-python-devel, AlmaLinux:8: python3-idle, AlmaLinux:8: python3-libs, AlmaLinux:8: python3-test, AlmaLinux:8: python3-tkinter</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* python: Virtual environment (venv) activation scripts don't quote paths (CVE-2024-9287)
  * python: Improper validation of IPv6 and IPvFuture addresses (CVE-2024-11168)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:10779"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-03332</id>
    <title>bdu:2025-03332</title>
    <updated>2026-10-02T23:51:45.705642+00:00</updated>
    <content>bdu:2025-03332</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-03332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2024-9287</id>
    <title>BELL-CVE-2024-9287</title>
    <updated>2026-10-02T23:51:45.705672+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:stream: python3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2024-9287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-libpython-2024-9287</id>
    <title>BIT-libpython-2024-9287 — Virtual environment (venv) activation scripts don't quote paths</title>
    <updated>2026-10-02T23:51:45.705713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: libpython</p>
<p>A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-libpython-2024-9287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0422</id>
    <title>certfr-2025-avi-0422 — De multiples vulnérabilités ont été découvertes dans IBM QRadar SIEM. Certaines d'entre elles permettent à un attaquant…</title>
    <updated>2026-10-02T23:51:45.705757+00:00</updated>
    <content>certfr-2025-avi-0422</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0422"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</id>
    <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
    <updated>2026-10-02T23:51:45.705784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cassandra-fips</p>
<p>Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258733</id>
    <title>EUVD-2026-258733</title>
    <updated>2026-10-02T23:51:45.705848+00:00</updated>
    <content>EUVD-2026-258733</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258733"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-9287</id>
    <title>fkie_cve-2024-9287</title>
    <updated>2026-10-02T23:51:45.705885+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-9287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-grqq-hcc7-crmr</id>
    <title>GHSA-grqq-hcc7-crmr</title>
    <updated>2026-10-02T23:51:45.705928+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-grqq-hcc7-crmr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2024-9287</id>
    <title>msrc_CVE-2024-9287 — Virtual environment (venv) activation scripts don't quote paths</title>
    <updated>2026-10-02T23:51:45.705964+00:00</updated>
    <content>msrc_CVE-2024-9287</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2024-9287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-2481</id>
    <title>OESA-2024-2481 — python3 security update</title>
    <updated>2026-10-02T23:51:45.705998+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: python3</p>
<p>Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.

Security Fix(es):

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment &amp;quot;activation&amp;quot; scripts (ie &amp;quot;source venv/bin/activate&amp;quot;). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren&amp;apos;t activated before being used (ie &amp;quot;./venv/bin/python&amp;quot;) are not affected.(CVE-2024-9287)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-2481"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14426-1</id>
    <title>openSUSE-SU-2024:14426-1 — python310-virtualenv-20.26.6-1.1 on GA media</title>
    <updated>2026-10-02T23:51:45.706048+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-virtualenv-20.26.6-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:14426-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2025:6294</id>
    <title>RHBA-2025:6294 — Red Hat Bug Fix Advisory: python3.12 bug fix and enhancement update</title>
    <updated>2026-10-02T23:51:45.706079+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python: cpython: tarfile: ReDos via excessive backtracking while parsing header values python: Virtual environment (venv) activation scripts don't quote paths python: Unbounded memory buffering in SelectorSocketTransport.writelines() python: cpython: URL parser allowed square brackets in domain names</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2025:6294"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:3760-1</id>
    <title>SUSE-SU-2024:3760-1 — Security update for python3</title>
    <updated>2026-10-02T23:51:45.706115+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:3760-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-9287</id>
    <title>UBUNTU-CVE-2024-9287</title>
    <updated>2026-10-02T23:51:45.706140+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:20.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.9, Ubuntu:22.04:LTS: python3.10, Ubuntu:Pro:22.04:LTS: python3.11 and 1 more</p>
<p>A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-9287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2025-053</id>
    <title>VDE-2025-053 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
    <updated>2026-10-02T23:51:45.706203+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Coreutils: heap overflow in split --line-bytes with very long lines Unprivileged overlay + shiftfs read access Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file SSL_select_next_proto buffer overread Remote Code Execution in pypa/setuptools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2025-053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3270</id>
    <title>WID-SEC-W-2024-3270 — Python: Schwachstelle ermöglicht Codeausführung</title>
    <updated>2026-10-02T23:51:45.706306+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Python und Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3270"/>
  </entry>
</feed>
