<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T18:43:57.598356+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-82049</id>
    <title>BELL-CVE-2026-82049</title>
    <updated>2026-10-02T18:43:57.843126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:stream: python3, BellSoft Hardened Containers:stream: python3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-82049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-libpython-2026-82049</id>
    <title>BIT-libpython-2026-82049 — tarfile extraction filters allow file modification and content disclosure via hard link to symlink</title>
    <updated>2026-10-02T18:43:57.843185+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: libpython</p>
<p>In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-libpython-2026-82049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1167</id>
    <title>certfr-2026-avi-1167 — De multiples vulnérabilités ont été découvertes dans Python. Certaines d'entre elles permettent à un attaquant de provo…</title>
    <updated>2026-10-02T18:43:57.843247+00:00</updated>
    <content>certfr-2026-avi-1167</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1167"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-382003</id>
    <title>EUVD-2026-382003</title>
    <updated>2026-10-02T18:43:57.843267+00:00</updated>
    <content>EUVD-2026-382003</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-382003"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-82049</id>
    <title>fkie_cve-2026-82049</title>
    <updated>2026-10-02T18:43:57.843280+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-82049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-ghff-gcpf-9r9p</id>
    <title>GHSA-ghff-gcpf-9r9p</title>
    <updated>2026-10-02T18:43:57.843302+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-ghff-gcpf-9r9p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-82049</id>
    <title>msrc_CVE-2026-82049 — tarfile extraction filters allow file modification and content disclosure via hard link to symlink</title>
    <updated>2026-10-02T18:43:57.843317+00:00</updated>
    <content>msrc_CVE-2026-82049</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-82049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4009</id>
    <title>OESA-2026-4009 — python3 security update</title>
    <updated>2026-10-02T18:43:57.843333+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python3</p>
<p>Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.

Security Fix(es):</p>
<p>The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.(CVE-2026-15806)</p>
<p>The &amp;qu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:65505</id>
    <title>RHSA-2026:65505 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
    <updated>2026-10-02T18:43:57.843376+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python: Python: Information disclosure due to incorrect URL scheme matching python: Python stringprep module: Incorrect domain name processing breaks IDNA interoperability python: Python tarfile module: Directory traversal allows creation of empty directories outside extraction destination python: Python tarfile module: File modification and content disclosure via crafted archives</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:65505"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82049</id>
    <title>UBUNTU-CVE-2026-82049</title>
    <updated>2026-10-02T18:43:57.843397+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.8 and 11 more</p>
<p>In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82049"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3367</id>
    <title>WID-SEC-W-2026-3367 — Python: Schwachstelle ermöglicht Manipulation und Offenlegung von Daten</title>
    <updated>2026-10-02T18:43:57.843443+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Python ausnutzen, um Daten zu manipulieren oder offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3367"/>
  </entry>
</feed>
