<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 15:29:54 +0000</lastBuildDate>
    <item>
      <title>ALSA-2019:3335 — Moderate: python27:2.7 security and bug fix update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2019:3335</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python-psycopg2-doc, AlmaLinux:8: python2-Cython, AlmaLinux:8: python2-PyMySQL, AlmaLinux:8: python2-attrs, AlmaLinux:8: python2-chardet, AlmaLinux:8: python2-coverage, AlmaLinux:8: python2-dns, AlmaLinux:8: python2-docs, AlmaLinux:8: python2-docs-info, AlmaLinux:8: python2-docutils and 17 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code execution (CVE-2019-6446)&lt;/p&gt;
&lt;p&gt;* python: CRLF injection via the query part of the url passed to urlopen() (CVE-2019-9740)&lt;/p&gt;
&lt;p&gt;* python: CRLF injection via the path part of the url passed to urlopen() (CVE-2019-9947)&lt;/p&gt;
&lt;p&gt;* python: Undocumented local_file protocol allows remote attackers to bypass protection mechanisms (CVE-2019-9948)&lt;/p&gt;
&lt;p&gt;* python-urllib3: CRLF injection due to not encoding the &amp;#39;\r\n&amp;#39; sequence leading to possible attack on internal service (CVE-2019-11236)&lt;/p&gt;
&lt;p&gt;* python-urllib3: Certification mishandle when error should be thrown (CVE-2019-11324)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python-psycopg2-doc, AlmaLinux:8: python2-Cython, AlmaLinux:8: python2-PyMySQL, AlmaLinux:8: python2-attrs, AlmaLinux:8: python2-chardet, AlmaLinux:8: python2-coverage, AlmaLinux:8: python2-dns, AlmaLinux:8: python2-docs, AlmaLinux:8: python2-docs-info, AlmaLinux:8: python2-docutils and 17 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code execution (CVE-2019-6446)&lt;/p&gt;
&lt;p&gt;* python: CRLF injection via the query part of the url passed to urlopen() (CVE-2019-9740)&lt;/p&gt;
&lt;p&gt;* python: CRLF injection via the path part of the url passed to urlopen() (CVE-2019-9947)&lt;/p&gt;
&lt;p&gt;* python: Undocumented local_file protocol allows remote attackers to bypass protection mechanisms (CVE-2019-9948)&lt;/p&gt;
&lt;p&gt;* python-urllib3: CRLF injection due to not encoding the &amp;#39;\r\n&amp;#39; sequence leading to possible attack on internal service (CVE-2019-11236)&lt;/p&gt;
&lt;p&gt;* python-urllib3: Certification mishandle when error should be thrown (CVE-2019-11324)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2019:3335</guid>
    </item>
    <item>
      <title>bdu:2019-02105</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-02105</link>
      <description>bdu:2019-02105</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-02105</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2019-11324 — CVE-2019-11324 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2019-11324</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2019-11324</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2019-11324 — Improper Certificate Validation in urllib3</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2019-11324</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the `ssl_context`, `ca_certs`, or `ca_certs_dir` argument.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the `ssl_context`, `ca_certs`, or `ca_certs_dir` argument.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2019-11324</guid>
    </item>
    <item>
      <title>certfr-2022-avi-267 — De multiples vulnérabilités ont été découvertes dans Juniper Networks
Junos Space. Elles permettent à un attaquant de p…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-267</link>
      <description>certfr-2022-avi-267</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-267</guid>
    </item>
    <item>
      <title>EUVD-2026-54331</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-54331</link>
      <description>EUVD-2026-54331</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-54331</guid>
    </item>
    <item>
      <title>fkie_cve-2019-11324</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-11324</link>
      <description>&lt;p&gt;The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-11324</guid>
    </item>
    <item>
      <title>GHSA-mh33-7rrq-662w — Improper Certificate Validation in urllib3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mh33-7rrq-662w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: urllib3&lt;/p&gt;
&lt;p&gt;The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the `ssl_context`, `ca_certs`, or `ca_certs_dir` argument.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: urllib3&lt;/p&gt;
&lt;p&gt;The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the `ssl_context`, `ca_certs`, or `ca_certs_dir` argument.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mh33-7rrq-662w</guid>
    </item>
    <item>
      <title>gsd-2019-11324</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-11324</link>
      <description>gsd-2019-11324</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-11324</guid>
    </item>
    <item>
      <title>msrc_CVE-2019-11324 — The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is diffe…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2019-11324</link>
      <description>msrc_CVE-2019-11324</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2019-11324</guid>
    </item>
    <item>
      <title>openSUSE-SU-2019:2131-1 — Security update for python-urllib3</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2019:2131-1</link>
      <description>&lt;p&gt;Security update for python-urllib3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-urllib3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2019:2131-1</guid>
    </item>
    <item>
      <title>PYSEC-2019-133</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2019-133</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: urllib3&lt;/p&gt;
&lt;p&gt;The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: urllib3&lt;/p&gt;
&lt;p&gt;The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2019-133</guid>
    </item>
    <item>
      <title>RHBA-2020:2785 — Red Hat Bug Fix Advisory: OpenShift Container Platform 4.4.11 packages update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2020:2785</link>
      <description>&lt;p&gt;python-urllib3: CRLF injection due to not encoding the &amp;#39;\r\n&amp;#39; sequence leading to possible attack on internal service python-urllib3: Certification mishandle when error should be thrown&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-urllib3: CRLF injection due to not encoding the &amp;#39;\r\n&amp;#39; sequence leading to possible attack on internal service python-urllib3: Certification mishandle when error should be thrown&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2020:2785</guid>
    </item>
    <item>
      <title>SUSE-SU-2019:2300-1 — Security update for python-urllib3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2019:2300-1</link>
      <description>&lt;p&gt;Security update for python-urllib3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-urllib3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2019:2300-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2019-11324</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-11324</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: python-urllib3&lt;/p&gt;
&lt;p&gt;The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: python-urllib3&lt;/p&gt;
&lt;p&gt;The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-11324</guid>
    </item>
  </channel>
</rss>
