<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:56:13.320360+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:23323</id>
    <title>ALSA-2025:23323 — Moderate: python3.12 security update</title>
    <updated>2026-10-02T20:56:14.078729+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: python3.12, AlmaLinux:9: python3.12-debug, AlmaLinux:9: python3.12-devel, AlmaLinux:9: python3.12-idle, AlmaLinux:9: python3.12-libs, AlmaLinux:9: python3.12-test, AlmaLinux:9: python3.12-tkinter</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked (CVE-2025-8291)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:23323"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-00313</id>
    <title>bdu:2026-00313</title>
    <updated>2026-10-02T20:56:14.078823+00:00</updated>
    <content>bdu:2026-00313</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-00313"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-libpython-2025-8291</id>
    <title>BIT-libpython-2025-8291 — ZIP64 End of Central Directory (EOCD) Locator record offset not checked</title>
    <updated>2026-10-02T20:56:14.078842+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: libpython</p>
<p>The 'zipfile' module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the 'zipfile' module
compared to other ZIP implementations.</p>
<p>Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-libpython-2025-8291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0851</id>
    <title>certfr-2025-avi-0851 — Une vulnérabilité a été découverte dans Python. Elle permet à un attaquant de provoquer un problème de sécurité non spé…</title>
    <updated>2026-10-02T20:56:14.078868+00:00</updated>
    <content>certfr-2025-avi-0851</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0851"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-jy81919</id>
    <title>Withdrawn: CLEANSTART-2026-JY81919 — Security fixes in python3 3.14.0-r0</title>
    <updated>2026-10-02T20:56:14.078884+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: python3</p>
<p>Package python3 version 3.14.0-r0 fixes 1 vulnerabilities: CVE-2025-8291</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-jy81919"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343262</id>
    <title>EUVD-2026-343262</title>
    <updated>2026-10-02T20:56:14.078904+00:00</updated>
    <content>EUVD-2026-343262</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343262"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-8291</id>
    <title>fkie_cve-2025-8291</title>
    <updated>2026-10-02T20:56:14.078916+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The 'zipfile' module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the 'zipfile' module
compared to other ZIP implementations.</p>
<p>Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-8291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-49g5-f6qw-8mm7</id>
    <title>GHSA-49g5-f6qw-8mm7</title>
    <updated>2026-10-02T20:56:14.078940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The 'zipfile' module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the 'zipfile' module
compared to other ZIP implementations.</p>
<p>Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-49g5-f6qw-8mm7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-8291</id>
    <title>msrc_CVE-2025-8291 — ZIP64 End of Central Directory (EOCD) Locator record offset not checked</title>
    <updated>2026-10-02T20:56:14.078959+00:00</updated>
    <content>msrc_CVE-2025-8291</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-8291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2574</id>
    <title>OESA-2025-2574 — python3 security update</title>
    <updated>2026-10-02T20:56:14.078975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: python3</p>
<p>Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.

Security Fix(es):</p>
<p>A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment  activation  scripts (ie  source venv/bin/activate ). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren t activated before being used (ie  ./venv/bin/python ) are not affected.(CVE-2024-9287)</p>
<p>The  zipfile  module in CPython would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value. This offset value was not used to locate the ZIP64 EOCD record; instead, the ZIP64 EOCD record was assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the  zipfile  module compared to other ZI…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15742-1</id>
    <title>openSUSE-SU-2025:15742-1 — python312-3.12.12-2.1 on GA media</title>
    <updated>2026-10-02T20:56:14.079010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python312-3.12.12-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15742-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:0353</id>
    <title>RHSA-2026:0353 — Red Hat Security Advisory: python3.12 security update</title>
    <updated>2026-10-02T20:56:14.079028+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:0353"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:21199-1</id>
    <title>SUSE-SU-2025:21199-1 — Security update for python311</title>
    <updated>2026-10-02T20:56:14.079044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python311</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:21199-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8291</id>
    <title>UBUNTU-CVE-2025-8291</title>
    <updated>2026-10-02T20:56:14.079059+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.8 and 8 more</p>
<p>The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8291"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2230</id>
    <title>WID-SEC-W-2025-2230 — Python (CPython Zipfile Module): Schwachstelle ermöglicht Manipulation von Dateien</title>
    <updated>2026-10-02T20:56:14.079103+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle im zipfile-Modul von CPython ausnutzen, um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2230"/>
  </entry>
</feed>
