<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 11:27:48 +0000</lastBuildDate>
    <item>
      <title>ALSA-2021:4151 — Moderate: python27:2.7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2021:4151</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: babel, AlmaLinux:8: python-nose-docs, AlmaLinux:8: python-psycopg2-doc, AlmaLinux:8: python-sqlalchemy-doc, AlmaLinux:8: python2-Cython, AlmaLinux:8: python2-PyMySQL, AlmaLinux:8: python2-attrs, AlmaLinux:8: python2-babel, AlmaLinux:8: python2-backports, AlmaLinux:8: python2-backports-ssl_match_hostname and 42 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Unsafe use of eval() on data retrieved via HTTP in the test suite (CVE-2020-27619)&lt;/p&gt;
&lt;p&gt;* python-jinja2: ReDoS vulnerability in the urlize filter (CVE-2020-28493)&lt;/p&gt;
&lt;p&gt;* python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code (CVE-2021-20095, CVE-2021-42771)&lt;/p&gt;
&lt;p&gt;* python-pygments: Infinite loop in SML lexer may lead to DoS (CVE-2021-20270)&lt;/p&gt;
&lt;p&gt;* python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters (CVE-2021-23336)&lt;/p&gt;
&lt;p&gt;* python-pygments: ReDoS in multiple lexers (CVE-2021-27291)&lt;/p&gt;
&lt;p&gt;* python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS (CVE-2021-28957)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: babel, AlmaLinux:8: python-nose-docs, AlmaLinux:8: python-psycopg2-doc, AlmaLinux:8: python-sqlalchemy-doc, AlmaLinux:8: python2-Cython, AlmaLinux:8: python2-PyMySQL, AlmaLinux:8: python2-attrs, AlmaLinux:8: python2-babel, AlmaLinux:8: python2-backports, AlmaLinux:8: python2-backports-ssl_match_hostname and 42 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Unsafe use of eval() on data retrieved via HTTP in the test suite (CVE-2020-27619)&lt;/p&gt;
&lt;p&gt;* python-jinja2: ReDoS vulnerability in the urlize filter (CVE-2020-28493)&lt;/p&gt;
&lt;p&gt;* python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code (CVE-2021-20095, CVE-2021-42771)&lt;/p&gt;
&lt;p&gt;* python-pygments: Infinite loop in SML lexer may lead to DoS (CVE-2021-20270)&lt;/p&gt;
&lt;p&gt;* python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters (CVE-2021-23336)&lt;/p&gt;
&lt;p&gt;* python-pygments: ReDoS in multiple lexers (CVE-2021-27291)&lt;/p&gt;
&lt;p&gt;* python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS (CVE-2021-28957)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2021:4151</guid>
    </item>
    <item>
      <title>certfr-2023-avi-0428 — De multiples vulnérabilités ont été découvertes dans les produits &lt;span
class="textit"&gt;Splunk&lt;/span&gt;. Certaines d'entre…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0428</link>
      <description>certfr-2023-avi-0428</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2023-avi-0428</guid>
    </item>
    <item>
      <title>fkie_cve-2021-20095</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-20095</link>
      <description>&lt;p&gt;Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-20095</guid>
    </item>
    <item>
      <title>GHSA-mqp6-6q54-7cxv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mqp6-6q54-7cxv</link>
      <description>&lt;p&gt;Relative Path Traversal in Babel 2.9.0 allows an attacker to load arbitrary locale files on disk and execute arbitrary code.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Relative Path Traversal in Babel 2.9.0 allows an attacker to load arbitrary locale files on disk and execute arbitrary code.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mqp6-6q54-7cxv</guid>
    </item>
    <item>
      <title>gsd-2021-20095</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-20095</link>
      <description>gsd-2021-20095</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-20095</guid>
    </item>
    <item>
      <title>OESA-2021-1194 — babel security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1194</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: babel&lt;/p&gt;
&lt;p&gt;Babel is an integrated collection of utilities that assist in internationalizing and localizing Python applications, with an emphasis on web-based applications.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Relative Path Traversal in Babel 2.9.0 allows an attacker to load arbitrary locale files on disk and execute arbitrary code.(CVE-2021-20095)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: babel&lt;/p&gt;
&lt;p&gt;Babel is an integrated collection of utilities that assist in internationalizing and localizing Python applications, with an emphasis on web-based applications.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Relative Path Traversal in Babel 2.9.0 allows an attacker to load arbitrary locale files on disk and execute arbitrary code.(CVE-2021-20095)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1194</guid>
    </item>
    <item>
      <title>RHSA-2021:3252 — Red Hat Security Advisory: python27 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:3252</link>
      <description>&lt;p&gt;python: Unsafe use of eval() on data retrieved via HTTP in the test suite python-jinja2: ReDoS vulnerability in the urlize filter python: Stack-based buffer overflow in PyCArg_repr in _ctypes/callproc.c python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code python-pygments: Infinite loop in SML lexer may lead to DoS python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters python-pygments: ReDoS in multiple lexers python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: Unsafe use of eval() on data retrieved via HTTP in the test suite python-jinja2: ReDoS vulnerability in the urlize filter python: Stack-based buffer overflow in PyCArg_repr in _ctypes/callproc.c python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code python-pygments: Infinite loop in SML lexer may lead to DoS python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters python-pygments: ReDoS in multiple lexers python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:3252</guid>
    </item>
    <item>
      <title>RHSA-2021:4151 — Red Hat Security Advisory: python27:2.7 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2021:4151</link>
      <description>&lt;p&gt;python: Unsafe use of eval() on data retrieved via HTTP in the test suite python-jinja2: ReDoS vulnerability in the urlize filter python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code python-pygments: Infinite loop in SML lexer may lead to DoS python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters python-pygments: ReDoS in multiple lexers python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: Unsafe use of eval() on data retrieved via HTTP in the test suite python-jinja2: ReDoS vulnerability in the urlize filter python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code python-pygments: Infinite loop in SML lexer may lead to DoS python: Web cache poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters python-pygments: ReDoS in multiple lexers python-lxml: Missing input sanitization for formaction HTML5 attributes may lead to XSS python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2021:4151</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-20095</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-20095</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-babel, Ubuntu:Pro:16.04:LTS: python-babel, Ubuntu:18.04:LTS: python-babel, Ubuntu:20.04:LTS: python-babel&lt;/p&gt;
&lt;p&gt;Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python-babel, Ubuntu:Pro:16.04:LTS: python-babel, Ubuntu:18.04:LTS: python-babel, Ubuntu:20.04:LTS: python-babel&lt;/p&gt;
&lt;p&gt;Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-20095</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0571 — Red Hat Enterprise Linux: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0571</link>
      <description>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuführen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um einen Cross-Site-Scripting-Angriff durchzuführen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, Dateien zu manipulieren und einen nicht spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0571</guid>
    </item>
  </channel>
</rss>
