<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:07:24.984586+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:10950</id>
    <title>ALSA-2026:10950 — Important: python3.12 security update</title>
    <updated>2026-10-02T17:07:25.042135+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python3.12, AlmaLinux:8: python3.12-debug, AlmaLinux:8: python3.12-devel, AlmaLinux:8: python3.12-idle, AlmaLinux:8: python3.12-libs, AlmaLinux:8: python3.12-rpm-macros, AlmaLinux:8: python3.12-test, AlmaLinux:8: python3.12-tkinter</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing (CVE-2025-59375)
  * python: Quadratic complexity in os.path.expandvars() with user-controlled template (CVE-2025-6075)
  * cpython: Out-of-memory when loading Plist (CVE-2025-13837)
  * cpython: Header injection via newlines in data URL mediatype in Python (CVE-2025-15282)
  * cpython: Header injection in http.cookies.Morsel in Python (CVE-2026-0672)
  * cpython: CPython: Logging Bypass in Legacy .pyc File Handling (CVE-2026-2297)
  * cpython: Incomplete control character validation in http.cookies (CVE-2026-3644)
  * cpython: Stack overflow parsing XML with deeply nested DTD content models (CVE-2026-4224)
  * python: Python: HTTP header injection via CR/LF in proxy tunnel headers (CVE-2026-1502)
  * python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules (CVE-2026-6100)
  * python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API (CVE-2026-4786)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgment…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:10950"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09515</id>
    <title>bdu:2026-09515</title>
    <updated>2026-10-02T17:07:25.042238+00:00</updated>
    <content>bdu:2026-09515</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09515"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-1502</id>
    <title>BELL-CVE-2026-1502</title>
    <updated>2026-10-02T17:07:25.042255+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: python3, Alpaquita:25: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:25: python3, BellSoft Hardened Containers:stream: python3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-1502"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-libpython-2026-1502</id>
    <title>BIT-libpython-2026-1502 — HTTP client proxy tunnel headers not validated for CR/LF</title>
    <updated>2026-10-02T17:07:25.042282+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: libpython</p>
<p>CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-libpython-2026-1502"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0426</id>
    <title>certfr-2026-avi-0426 — De multiples vulnérabilités ont été découvertes dans Python. Elles permettent à un attaquant de provoquer un contournem…</title>
    <updated>2026-10-02T17:07:25.042302+00:00</updated>
    <content>certfr-2026-avi-0426</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0426"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-351833</id>
    <title>EUVD-2026-351833</title>
    <updated>2026-10-02T17:07:25.042317+00:00</updated>
    <content>EUVD-2026-351833</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-351833"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-1502</id>
    <title>fkie_cve-2026-1502</title>
    <updated>2026-10-02T17:07:25.042327+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-1502"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hjxq-7w9q-2jw6</id>
    <title>GHSA-hjxq-7w9q-2jw6</title>
    <updated>2026-10-02T17:07:25.042347+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hjxq-7w9q-2jw6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-1502</id>
    <title>msrc_CVE-2026-1502 — HTTP client proxy tunnel headers not validated for CR/LF</title>
    <updated>2026-10-02T17:07:25.042359+00:00</updated>
    <content>msrc_CVE-2026-1502</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-1502"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2115</id>
    <title>OESA-2026-2115 — python3 security update</title>
    <updated>2026-10-02T17:07:25.042375+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python3</p>
<p>Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.

Security Fix(es):</p>
<p>CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.(CVE-2026-1502)</p>
<p>Mitgation of CVE-2026-4519 was incomplete. If the URL contained &amp;quot;%action&amp;quot; the mitigation could be bypassed for certain browser types the &amp;quot;webbrowser.open()&amp;quot; API could have commands injected into the underlying shell. See CVE-2026-4519 for details.(CVE-2026-4786)</p>
<p>Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition.</p>
<p>The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lz…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2115"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10647-1</id>
    <title>openSUSE-SU-2026:10647-1 — python310-3.10.20-6.1 on GA media</title>
    <updated>2026-10-02T17:07:25.042410+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-3.10.20-6.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10647-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10117</id>
    <title>RHSA-2026:10117 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T17:07:25.042429+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python: Python: HTTP header injection via CR/LF in proxy tunnel headers python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10117"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:19176</id>
    <title>RLSA-2026:19176 — Important: python3.14 security update</title>
    <updated>2026-10-02T17:07:25.042449+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: python3.14</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* cpython: wsgiref.headers.Headers allows header newline injection in Python (CVE-2026-0865)</p>
<p>* cpython: CPython: Logging Bypass in Legacy .pyc File Handling (CVE-2026-2297)</p>
<p>* cpython: Incomplete control character validation in http.cookies (CVE-2026-3644)</p>
<p>* cpython: Stack overflow parsing XML with deeply nested DTD content models (CVE-2026-4224)</p>
<p>* python: Python: Command-line option injection in webbrowser.open() via crafted URLs (CVE-2026-4519)</p>
<p>* python: Python: HTTP header injection via CR/LF in proxy tunnel headers (CVE-2026-1502)</p>
<p>* python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules (CVE-2026-6100)</p>
<p>* python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API (CVE-2026-4786)</p>
<p>* python: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. (CVE-2026-5713)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:19176"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:1818-1</id>
    <title>SUSE-SU-2026:1818-1 — Security update for python39</title>
    <updated>2026-10-02T17:07:25.042481+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python39</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:1818-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-1502</id>
    <title>UBUNTU-CVE-2026-1502</title>
    <updated>2026-10-02T17:07:25.042499+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:16.04:LTS: jython, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:18.04:LTS: jython, Ubuntu:Pro:18.04:LTS: python3.7 and 21 more</p>
<p>CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-1502"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1064</id>
    <title>WID-SEC-W-2026-1064 — CPython: Mehrere Schwachstellen</title>
    <updated>2026-10-02T17:07:25.042549+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in CPython ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1064"/>
  </entry>
</feed>
