<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:27:23 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:4151 — Moderate: python27:2.7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:4151</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: babel, AlmaLinux:8: python-nose-docs, AlmaLinux:8: python-psycopg2-doc, AlmaLinux:8: python-sqlalchemy-doc, AlmaLinux:8: python2-Cython, AlmaLinux:8: python2-PyMySQL, AlmaLinux:8: python2-attrs, AlmaLinux:8: python2-babel, AlmaLinux:8: python2-backports, AlmaLinux:8: python2-backports-ssl_match_hostname and 42 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Unsafe use of eval() on data retrieved via HTTP in the test suite (CVE-2020-27619)&lt;/p&gt;
&lt;p&gt;* python-jinja2: ReDoS vulnerability in the urlize filter (CVE-2020-28493)&lt;/p&gt;
&lt;p&gt;* python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code (CVE-2021-20095, CVE-2021-42771)&lt;/p&gt;
&lt;p&gt;* python-pygments: Infinite loop in SML lexer may lead to DoS (CVE-2021-20270)&lt;/p&gt;
&lt;p&gt;* python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters (CVE-2021-23336)&lt;/p&gt;
&lt;p&gt;* python-pygments: ReDoS in multiple lexers (CVE-2021-27291)&lt;/p&gt;
&lt;p&gt;* python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS (CVE-2021-28957)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: babel, AlmaLinux:8: python-nose-docs, AlmaLinux:8: python-psycopg2-doc, AlmaLinux:8: python-sqlalchemy-doc, AlmaLinux:8: python2-Cython, AlmaLinux:8: python2-PyMySQL, AlmaLinux:8: python2-attrs, AlmaLinux:8: python2-babel, AlmaLinux:8: python2-backports, AlmaLinux:8: python2-backports-ssl_match_hostname and 42 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Unsafe use of eval() on data retrieved via HTTP in the test suite (CVE-2020-27619)&lt;/p&gt;
&lt;p&gt;* python-jinja2: ReDoS vulnerability in the urlize filter (CVE-2020-28493)&lt;/p&gt;
&lt;p&gt;* python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code (CVE-2021-20095, CVE-2021-42771)&lt;/p&gt;
&lt;p&gt;* python-pygments: Infinite loop in SML lexer may lead to DoS (CVE-2021-20270)&lt;/p&gt;
&lt;p&gt;* python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters (CVE-2021-23336)&lt;/p&gt;
&lt;p&gt;* python-pygments: ReDoS in multiple lexers (CVE-2021-27291)&lt;/p&gt;
&lt;p&gt;* python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS (CVE-2021-28957)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:4151</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-27619 — CVE-2020-27619 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-27619</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-27619</guid>
    </item>
    <item>
      <title>BIT-libpython-2020-27619</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libpython-2020-27619</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libpython-2020-27619</guid>
    </item>
    <item>
      <title>certfr-2021-avi-791 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</link>
      <description>certfr-2021-avi-791</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2021-avi-791</guid>
    </item>
    <item>
      <title>EUVD-2026-46550</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-46550</link>
      <description>EUVD-2026-46550</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-46550</guid>
    </item>
    <item>
      <title>fkie_cve-2020-27619</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-27619</link>
      <description>&lt;p&gt;In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-27619</guid>
    </item>
    <item>
      <title>GHSA-22cq-cq7f-8jm3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-22cq-cq7f-8jm3</link>
      <description>&lt;p&gt;In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-22cq-cq7f-8jm3</guid>
    </item>
    <item>
      <title>gsd-2020-27619</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-27619</link>
      <description>gsd-2020-27619</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-27619</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-27619 — In Python 3 through 3.9.0 the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via H…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-27619</link>
      <description>msrc_CVE-2020-27619</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-27619</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:2332-1 — Security update for python3</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:2332-1</link>
      <description>&lt;p&gt;Security update for python3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:2332-1</guid>
    </item>
    <item>
      <title>RHSA-2021:3252 — Red Hat Security Advisory: python27 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3252</link>
      <description>&lt;p&gt;python: Unsafe use of eval() on data retrieved via HTTP in the test suite python-jinja2: ReDoS vulnerability in the urlize filter python: Stack-based buffer overflow in PyCArg_repr in _ctypes/callproc.c python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code python-pygments: Infinite loop in SML lexer may lead to DoS python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters python-pygments: ReDoS in multiple lexers python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: Unsafe use of eval() on data retrieved via HTTP in the test suite python-jinja2: ReDoS vulnerability in the urlize filter python: Stack-based buffer overflow in PyCArg_repr in _ctypes/callproc.c python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code python-pygments: Infinite loop in SML lexer may lead to DoS python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters python-pygments: ReDoS in multiple lexers python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3252</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:3865-1 — Security update for python36</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:3865-1</link>
      <description>&lt;p&gt;Security update for python36&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python36&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:3865-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-27619</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-27619</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:16.04:LTS: python3.5, Ubuntu:18.04:LTS: python3.6, Ubuntu:18.04:LTS: python3.7, Ubuntu:18.04:LTS: python3.8, Ubuntu:20.04:LTS: python3.8&lt;/p&gt;
&lt;p&gt;In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:16.04:LTS: python3.5, Ubuntu:18.04:LTS: python3.6, Ubuntu:18.04:LTS: python3.7, Ubuntu:18.04:LTS: python3.8, Ubuntu:20.04:LTS: python3.8&lt;/p&gt;
&lt;p&gt;In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-27619</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0227 — IBM QRadar SIEM: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0227</guid>
    </item>
  </channel>
</rss>
