<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:41:57 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:4151 — Moderate: python27:2.7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:4151</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: babel, AlmaLinux:8: python-nose-docs, AlmaLinux:8: python-psycopg2-doc, AlmaLinux:8: python-sqlalchemy-doc, AlmaLinux:8: python2-Cython, AlmaLinux:8: python2-PyMySQL, AlmaLinux:8: python2-attrs, AlmaLinux:8: python2-babel, AlmaLinux:8: python2-backports, AlmaLinux:8: python2-backports-ssl_match_hostname and 42 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Unsafe use of eval() on data retrieved via HTTP in the test suite (CVE-2020-27619)&lt;/p&gt;
&lt;p&gt;* python-jinja2: ReDoS vulnerability in the urlize filter (CVE-2020-28493)&lt;/p&gt;
&lt;p&gt;* python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code (CVE-2021-20095, CVE-2021-42771)&lt;/p&gt;
&lt;p&gt;* python-pygments: Infinite loop in SML lexer may lead to DoS (CVE-2021-20270)&lt;/p&gt;
&lt;p&gt;* python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters (CVE-2021-23336)&lt;/p&gt;
&lt;p&gt;* python-pygments: ReDoS in multiple lexers (CVE-2021-27291)&lt;/p&gt;
&lt;p&gt;* python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS (CVE-2021-28957)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: babel, AlmaLinux:8: python-nose-docs, AlmaLinux:8: python-psycopg2-doc, AlmaLinux:8: python-sqlalchemy-doc, AlmaLinux:8: python2-Cython, AlmaLinux:8: python2-PyMySQL, AlmaLinux:8: python2-attrs, AlmaLinux:8: python2-babel, AlmaLinux:8: python2-backports, AlmaLinux:8: python2-backports-ssl_match_hostname and 42 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Unsafe use of eval() on data retrieved via HTTP in the test suite (CVE-2020-27619)&lt;/p&gt;
&lt;p&gt;* python-jinja2: ReDoS vulnerability in the urlize filter (CVE-2020-28493)&lt;/p&gt;
&lt;p&gt;* python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code (CVE-2021-20095, CVE-2021-42771)&lt;/p&gt;
&lt;p&gt;* python-pygments: Infinite loop in SML lexer may lead to DoS (CVE-2021-20270)&lt;/p&gt;
&lt;p&gt;* python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters (CVE-2021-23336)&lt;/p&gt;
&lt;p&gt;* python-pygments: ReDoS in multiple lexers (CVE-2021-27291)&lt;/p&gt;
&lt;p&gt;* python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS (CVE-2021-28957)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:4151</guid>
    </item>
    <item>
      <title>bdu:2022-05230</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-05230</link>
      <description>bdu:2022-05230</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-05230</guid>
    </item>
    <item>
      <title>Withdrawn: BELL-CVE-2020-28493 — CVE-2020-28493 does not affect BellSoft software</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2020-28493</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2020-28493</guid>
    </item>
    <item>
      <title>BREW-ansible-CVE-2020-28493 — Regular Expression Denial of Service (ReDoS) in Jinja2</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-28493</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDOS vulnerability of the regex is mainly due to the sub-pattern [a-zA-Z0-9._-]+.[a-zA-Z0-9._-]+ This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible&lt;/p&gt;
&lt;p&gt;This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDOS vulnerability of the regex is mainly due to the sub-pattern [a-zA-Z0-9._-]+.[a-zA-Z0-9._-]+ This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cve-2020-28493</guid>
    </item>
    <item>
      <title>certfr-2022-avi-831 — De multiples vulnérabilités ont été découvertes dans les produits IBM.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-831</link>
      <description>certfr-2022-avi-831</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-831</guid>
    </item>
    <item>
      <title>EUVD-2026-165877</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-165877</link>
      <description>EUVD-2026-165877</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-165877</guid>
    </item>
    <item>
      <title>fkie_cve-2020-28493</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-28493</link>
      <description>&lt;p&gt;This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-28493</guid>
    </item>
    <item>
      <title>GHSA-g3rq-g295-4j3m — Regular Expression Denial of Service (ReDoS) in Jinja2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g3rq-g295-4j3m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Jinja2&lt;/p&gt;
&lt;p&gt;This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDOS vulnerability of the regex is mainly due to the sub-pattern [a-zA-Z0-9._-]+.[a-zA-Z0-9._-]+ This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Jinja2&lt;/p&gt;
&lt;p&gt;This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDOS vulnerability of the regex is mainly due to the sub-pattern [a-zA-Z0-9._-]+.[a-zA-Z0-9._-]+ This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g3rq-g295-4j3m</guid>
    </item>
    <item>
      <title>gsd-2020-28493</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-28493</link>
      <description>gsd-2020-28493</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-28493</guid>
    </item>
    <item>
      <title>msrc_CVE-2020-28493 — Regular Expression Denial of Service (ReDoS)</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2020-28493</link>
      <description>msrc_CVE-2020-28493</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2020-28493</guid>
    </item>
    <item>
      <title>OESA-2021-1190 — python-jinja2 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1190</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: python-jinja2&lt;/p&gt;
&lt;p&gt;Jinja2 is one of the most used template engines for Python. It is inspired by Django&amp;amp;apos;s templating system but extends it with an expressive language that gives template authors a more powerful set of tools. On top of that it adds sandboxed execution and optional automatic escaping for applications where security is important.&#13;
&#13;
Security Fix(es):&#13;
&#13;
This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.(CVE-2020-28493)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: python-jinja2&lt;/p&gt;
&lt;p&gt;Jinja2 is one of the most used template engines for Python. It is inspired by Django&amp;amp;apos;s templating system but extends it with an expressive language that gives template authors a more powerful set of tools. On top of that it adds sandboxed execution and optional automatic escaping for applications where security is important.&#13;
&#13;
Security Fix(es):&#13;
&#13;
This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.(CVE-2020-28493)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1190</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:11208-1 — python36-Jinja2-3.0.1-3.2 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11208-1</link>
      <description>&lt;p&gt;python36-Jinja2-3.0.1-3.2 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python36-Jinja2-3.0.1-3.2 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:11208-1</guid>
    </item>
    <item>
      <title>PYSEC-2021-66</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2021-66</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jinja2&lt;/p&gt;
&lt;p&gt;This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jinja2&lt;/p&gt;
&lt;p&gt;This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2021-66</guid>
    </item>
    <item>
      <title>RHSA-2021:3252 — Red Hat Security Advisory: python27 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3252</link>
      <description>&lt;p&gt;python: Unsafe use of eval() on data retrieved via HTTP in the test suite python-jinja2: ReDoS vulnerability in the urlize filter python: Stack-based buffer overflow in PyCArg_repr in _ctypes/callproc.c python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code python-pygments: Infinite loop in SML lexer may lead to DoS python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters python-pygments: ReDoS in multiple lexers python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: Unsafe use of eval() on data retrieved via HTTP in the test suite python-jinja2: ReDoS vulnerability in the urlize filter python: Stack-based buffer overflow in PyCArg_repr in _ctypes/callproc.c python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code python-pygments: Infinite loop in SML lexer may lead to DoS python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters python-pygments: ReDoS in multiple lexers python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3252</guid>
    </item>
    <item>
      <title>SUSE-SU-2021:0601-1 — Security update for python-Jinja2</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2021:0601-1</link>
      <description>&lt;p&gt;Security update for python-Jinja2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Jinja2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2021:0601-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-28493</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-28493</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jinja2, Ubuntu:Pro:16.04:LTS: jinja2, Ubuntu:Pro:18.04:LTS: jinja2, Ubuntu:20.04:LTS: jinja2&lt;/p&gt;
&lt;p&gt;This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: jinja2, Ubuntu:Pro:16.04:LTS: jinja2, Ubuntu:Pro:18.04:LTS: jinja2, Ubuntu:20.04:LTS: jinja2&lt;/p&gt;
&lt;p&gt;This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-28493</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0794 — Dell ECS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0794</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Dell ECS ausnutzen, um seine Privilegien zu erweitern, beliebigen Programmcode mit Administratorrechten auszuführen, Informationen offenzulegen, Dateien zu manipulieren, einen Cross-Site-Scripting-Angriff durchzuführen, Sicherheitsvorkehrungen zu umgehen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0794</guid>
    </item>
  </channel>
</rss>
