<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:36:24.878737+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-19672</id>
    <title>BELL-CVE-2026-19672</title>
    <updated>2026-10-03T13:36:25.113699+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: python3, Alpaquita:25: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:25: python3, BellSoft Hardened Containers:stream: python3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-19672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-libpython-2026-19672</id>
    <title>BIT-libpython-2026-19672 — tarfile extraction filter bypass allows creation of directories outside the destination</title>
    <updated>2026-10-03T13:36:25.113760+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: libpython</p>
<p>The tarfile module's tar and data
 extraction filters created directories outside the destination for 
members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.</p>
<p>Only
 empty directories are created outside the destination. Member contents 
are still extracted inside it. To return to the destination the member's
 name must contain the destination directory's own final component, so 
extraction into a secure randomised directory is not affected.</p>
<p>This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-libpython-2026-19672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1062</id>
    <title>certfr-2026-avi-1062 — Une vulnérabilité a été découverte dans Python. Elle permet à un attaquant de provoquer un contournement de la politiqu…</title>
    <updated>2026-10-03T13:36:25.113793+00:00</updated>
    <content>certfr-2026-avi-1062</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-360316</id>
    <title>EUVD-2026-360316</title>
    <updated>2026-10-03T13:36:25.113810+00:00</updated>
    <content>EUVD-2026-360316</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-360316"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-19672</id>
    <title>fkie_cve-2026-19672</title>
    <updated>2026-10-03T13:36:25.113822+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The tarfile module's tar and data
 extraction filters created directories outside the destination for 
members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.</p>
<p>Only
 empty directories are created outside the destination. Member contents 
are still extracted inside it. To return to the destination the member's
 name must contain the destination directory's own final component, so 
extraction into a secure randomised directory is not affected.</p>
<p>This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-19672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-prxg-vvhf-mgqq</id>
    <title>GHSA-prxg-vvhf-mgqq</title>
    <updated>2026-10-03T13:36:25.113848+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The tarfile module's tar and data
 extraction filters created directories outside the destination for 
members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given.</p>
<p>Only
 empty directories are created outside the destination. Member contents 
are still extracted inside it. To return to the destination the member's
 name must contain the destination directory's own final component, so 
extraction into a secure randomised directory is not affected.</p>
<p>This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-prxg-vvhf-mgqq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-19672</id>
    <title>msrc_CVE-2026-19672 — tarfile extraction filter bypass allows creation of directories outside the destination</title>
    <updated>2026-10-03T13:36:25.113869+00:00</updated>
    <content>msrc_CVE-2026-19672</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-19672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4009</id>
    <title>OESA-2026-4009 — python3 security update</title>
    <updated>2026-10-03T13:36:25.113884+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python3</p>
<p>Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.

Security Fix(es):</p>
<p>The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.(CVE-2026-15806)</p>
<p>The &amp;qu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11817-1</id>
    <title>openSUSE-SU-2026:11817-1 — python313-3.13.15-1.1 on GA media</title>
    <updated>2026-10-03T13:36:25.113927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python313-3.13.15-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11817-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:65505</id>
    <title>RHSA-2026:65505 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-03T13:36:25.113946+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python: Python: Information disclosure due to incorrect URL scheme matching python: Python stringprep module: Incorrect domain name processing breaks IDNA interoperability python: Python tarfile module: Directory traversal allows creation of empty directories outside extraction destination python: Python tarfile module: File modification and content disclosure via crafted archives</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:65505"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:4411-1</id>
    <title>SUSE-SU-2026:4411-1 — Security update for python</title>
    <updated>2026-10-03T13:36:25.113966+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:4411-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-19672</id>
    <title>UBUNTU-CVE-2026-19672</title>
    <updated>2026-10-03T13:36:25.113982+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.8 and 7 more</p>
<p>The tarfile module's tar and data  extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given. Only  empty directories are created outside the destination. Member contents are still extracted inside it. To return to the destination the member's  name must contain the destination directory's own final component, so extraction into a secure randomised directory is not affected. This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-19672"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3016</id>
    <title>WID-SEC-W-2026-3016 — CPython: Schwachstelle ermöglicht Manipulation von Dateien</title>
    <updated>2026-10-03T13:36:25.114029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in CPython ausnutzen, um Dateien zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3016"/>
  </entry>
</feed>
