<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:33:05.872471+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:23530</id>
    <title>ALSA-2025:23530 — Important: python39:3.9 security update</title>
    <updated>2026-10-03T07:33:06.317409+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python39, AlmaLinux:8: python39-Cython, AlmaLinux:8: python39-PyMySQL, AlmaLinux:8: python39-attrs, AlmaLinux:8: python39-cffi, AlmaLinux:8: python39-chardet, AlmaLinux:8: python39-cryptography, AlmaLinux:8: python39-debug, AlmaLinux:8: python39-devel, AlmaLinux:8: python39-idle and 39 more</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* python: Invalid value for OpenSSL API may cause Buffer over-read when NPN is used (CVE-2024-5642)
  * python: Virtual environment (venv) activation scripts don't quote paths (CVE-2024-9287)
  * python: Improper validation of IPv6 and IPvFuture addresses (CVE-2024-11168)
  * python: cpython: URL parser allowed square brackets in domain names (CVE-2025-0938)
  * cpython: python: CPython DecodeError Handling Vulnerability (CVE-2025-4516)
  * cpython: Tarfile extracts filtered members when errorlevel=0 (CVE-2025-4435)
  * cpython: python: Extraction filter bypass for linking outside extraction directory (CVE-2025-4330)
  * python: cpython: Arbitrary writes via tarfile realpath overflow (CVE-2025-4517)
  * cpython: python: Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory (CVE-2025-4138)
  * cpython: Python HTMLParser quadratic complexity (CVE-2025-6069)
  * cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked (CVE-2025-8291)
  * python: Quadratic complexity in os.path.expandvars() with user-controlled template (CVE-2025-6075)</p>
<p>For more details about the security issue(s), including th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:23530"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-10930</id>
    <title>bdu:2025-10930</title>
    <updated>2026-10-03T07:33:06.317552+00:00</updated>
    <content>bdu:2025-10930</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-10930"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-4516</id>
    <title>BELL-CVE-2025-4516</title>
    <updated>2026-10-03T07:33:06.317571+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:stream: python3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-4516"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-libpython-2025-4516</id>
    <title>BIT-libpython-2025-4516 — Use-after-free in "unicode_escape" decoder with error handler</title>
    <updated>2026-10-03T07:33:06.317594+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: libpython</p>
<p>There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-libpython-2025-4516"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0415</id>
    <title>certfr-2025-avi-0415 — Une vulnérabilité a été découverte dans Python. Elle permet à un attaquant de provoquer un déni de service.</title>
    <updated>2026-10-03T07:33:06.317617+00:00</updated>
    <content>certfr-2025-avi-0415</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0415"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</id>
    <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
    <updated>2026-10-03T07:33:06.317631+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: cassandra-fips</p>
<p>Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343267</id>
    <title>EUVD-2026-343267</title>
    <updated>2026-10-03T07:33:06.317661+00:00</updated>
    <content>EUVD-2026-343267</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343267"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-4516</id>
    <title>fkie_cve-2025-4516</title>
    <updated>2026-10-03T07:33:06.317674+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-4516"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j8r3-cghj-9jhg</id>
    <title>GHSA-j8r3-cghj-9jhg</title>
    <updated>2026-10-03T07:33:06.317698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j8r3-cghj-9jhg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-043-06</id>
    <title>ICSA-26-043-06 — Siemens SINEC OS</title>
    <updated>2026-10-03T07:33:06.317713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns.  This makes it possible in some scenarios that both the function and its caller call freeaddrinfo() for the same allocated memory block.  A similar problem was reported in Apple libpcap, to which Apple assigned CVE-2023-40400. An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal. A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `fr…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-043-06"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-4516</id>
    <title>msrc_CVE-2025-4516 — Use-after-free in "unicode_escape" decoder with error handler</title>
    <updated>2026-10-03T07:33:06.317947+00:00</updated>
    <content>msrc_CVE-2025-4516</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-4516"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2288</id>
    <title>OESA-2025-2288 — python3 security update</title>
    <updated>2026-10-03T07:33:06.317964+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: python3</p>
<p>Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.

Security Fix(es):</p>
<p>There is an issue in CPython when using `bytes.decode(&amp;quot;unicode_escape&amp;quot;, error=&amp;quot;ignore|replace&amp;quot;)`. If you are not using the &amp;quot;unicode_escape&amp;quot; encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.(CVE-2025-4516)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2288"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15154-1</id>
    <title>openSUSE-SU-2025:15154-1 — python313-3.13.3-3.1 on GA media</title>
    <updated>2026-10-03T07:33:06.317990+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python313-3.13.3-3.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15154-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ssa-089022</id>
    <title>SSA-089022 — SSA-089022: Multiple Vulnerabilities in Third-Party Components in SINEC OS before V3.3</title>
    <updated>2026-10-03T07:33:06.318006+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution. In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns.  This makes it possible in some scenarios that both the function and its caller call freeaddrinfo() for the same allocated memory block.  A similar problem was reported in Apple libpcap, to which Apple assigned CVE-2023-40400. An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal. A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. A use-after-free vulnerability was discovered in BusyBox v.1.36.1 via a crafted awk pattern in the awk.c copyvar function. A heap-buffer-overflow was discovered in BusyBox v.1.36.1 in the next_token function at awk.c:1159. libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `fr…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ssa-089022"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:01877-1</id>
    <title>SUSE-SU-2025:01877-1 — Security update for python3</title>
    <updated>2026-10-03T07:33:06.318231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:01877-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4516</id>
    <title>UBUNTU-CVE-2025-4516</title>
    <updated>2026-10-03T07:33:06.318247+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.9, Ubuntu:22.04:LTS: python3.10, Ubuntu:Pro:22.04:LTS: python3.11, Ubuntu:24.04:LTS: python3.12, Ubuntu:25.10: python3.14, Ubuntu:26.04:LTS: python3.14</p>
<p>There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-4516"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1080</id>
    <title>WID-SEC-W-2025-1080 — CPython: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T07:33:06.318281+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in CPython ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1080"/>
  </entry>
</feed>
