<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:35:49 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:4766 — Low: python3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:4766</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3.11, AlmaLinux:9: python3.11-debug, AlmaLinux:9: python3.11-devel, AlmaLinux:9: python3.11-idle, AlmaLinux:9: python3.11-libs, AlmaLinux:9: python3.11-test, AlmaLinux:9: python3.11-tkinter&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: incorrect IPv4 and IPv6 private ranges (CVE-2024-4032)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3.11, AlmaLinux:9: python3.11-debug, AlmaLinux:9: python3.11-devel, AlmaLinux:9: python3.11-idle, AlmaLinux:9: python3.11-libs, AlmaLinux:9: python3.11-test, AlmaLinux:9: python3.11-tkinter&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: incorrect IPv4 and IPv6 private ranges (CVE-2024-4032)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:4766</guid>
    </item>
    <item>
      <title>bdu:2024-05196</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-05196</link>
      <description>bdu:2024-05196</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-05196</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-4032</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-4032</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:stream: python3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:stream: python3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-4032</guid>
    </item>
    <item>
      <title>BIT-libpython-2024-4032 — Incorrect IPv4 and IPv6 private ranges</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libpython-2024-4032</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.&lt;/p&gt;
&lt;p&gt;CPython 3.12.4 and 3.13.0 contain updated information from these registries and thus have the intended behavior.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.&lt;/p&gt;
&lt;p&gt;CPython 3.12.4 and 3.13.0 contain updated information from these registries and thus have the intended behavior.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libpython-2024-4032</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0540 — De multiples vulnérabilités ont été découvertes dans Python. Elles permettent à un attaquant de provoquer un contournem…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0540</link>
      <description>certfr-2024-avi-0540</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0540</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CQ39979 — Security fixes in cassandra 5.0.6-r2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cq39979</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra&lt;/p&gt;
&lt;p&gt;Package cassandra version 5.0.6-r2 fixes 26 vulnerabilities: ghsa-72hv-8253-57qq, ghsa-pr98-23f8-jwxv, ghsa-25qh-j22f-pwp8, ghsa-6v67-2wr5-gvf4, ghsa-qqpg-mvqg-649v...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra&lt;/p&gt;
&lt;p&gt;Package cassandra version 5.0.6-r2 fixes 26 vulnerabilities: ghsa-72hv-8253-57qq, ghsa-pr98-23f8-jwxv, ghsa-25qh-j22f-pwp8, ghsa-6v67-2wr5-gvf4, ghsa-qqpg-mvqg-649v...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cq39979</guid>
    </item>
    <item>
      <title>EUVD-2026-258651</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258651</link>
      <description>EUVD-2026-258651</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258651</guid>
    </item>
    <item>
      <title>fkie_cve-2024-4032</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-4032</link>
      <description>&lt;p&gt;The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.&lt;/p&gt;
&lt;p&gt;CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.&lt;/p&gt;
&lt;p&gt;CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-4032</guid>
    </item>
    <item>
      <title>GHSA-mh6q-v4mp-2cc7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mh6q-v4mp-2cc7</link>
      <description>&lt;p&gt;The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.&lt;/p&gt;
&lt;p&gt;CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.&lt;/p&gt;
&lt;p&gt;CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mh6q-v4mp-2cc7</guid>
    </item>
    <item>
      <title>gsd-2024-4032</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-4032</link>
      <description>gsd-2024-4032</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-4032</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-4032 — Incorrect IPv4 and IPv6 private ranges</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-4032</link>
      <description>msrc_CVE-2024-4032</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-4032</guid>
    </item>
    <item>
      <title>OESA-2024-1940 — python3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1940</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A defect was discovered in the Python “ssl” module where there is a memory
race condition with the ssl.SSLContext methods “cert_store_stats()” and
“get_ca_certs()”. The race condition can be triggered if the methods are
called at the same time as certificates are loaded into the SSLContext,
such as during the TLS handshake with a certificate directory configured.
This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.(CVE-2024-0397)&#13;
&#13;
The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.&#13;
&#13;
CPython 3.12.4 and 3.13.0a6 contain updated information from…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A defect was discovered in the Python “ssl” module where there is a memory
race condition with the ssl.SSLContext methods “cert_store_stats()” and
“get_ca_certs()”. The race condition can be triggered if the methods are
called at the same time as certificates are loaded into the SSLContext,
such as during the TLS handshake with a certificate directory configured.
This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.(CVE-2024-0397)&#13;
&#13;
The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.&#13;
&#13;
CPython 3.12.4 and 3.13.0a6 contain updated information from…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1940</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14078-1 — python38-3.8.19-4.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14078-1</link>
      <description>&lt;p&gt;python38-3.8.19-4.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python38-3.8.19-4.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14078-1</guid>
    </item>
    <item>
      <title>RHSA-2024:5962 — Red Hat Security Advisory: python39:3.9 and python39-devel:3.9 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:5962</link>
      <description>&lt;p&gt;python: incorrect IPv4 and IPv6 private ranges pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools cpython: python: email module doesn&amp;#39;t properly quotes newlines in email headers, allowing header injection python: cpython: Iterating over a malicious ZIP file may lead to Denial of Service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: incorrect IPv4 and IPv6 private ranges pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools cpython: python: email module doesn&amp;#39;t properly quotes newlines in email headers, allowing header injection python: cpython: Iterating over a malicious ZIP file may lead to Denial of Service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:5962</guid>
    </item>
    <item>
      <title>SUSE-EL-9-CLIENT-TOOLS-2024-4029 — Security update for SUSE Manager Salt Bundle</title>
      <link>https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2024-4029</link>
      <description>&lt;p&gt;Security update for SUSE Manager Salt Bundle&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for SUSE Manager Salt Bundle&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2024-4029</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-4032</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4032</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:20.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.9, Ubuntu:22.04:LTS: python3.10, Ubuntu:Pro:22.04:LTS: python3.11 and 1 more&lt;/p&gt;
&lt;p&gt;The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:20.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.9, Ubuntu:22.04:LTS: python3.10, Ubuntu:Pro:22.04:LTS: python3.11 and 1 more&lt;/p&gt;
&lt;p&gt;The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4032</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1396 — Python: Mehrere Schwachstellen ermöglichen Manipulation von Dateien und Umgehung von Sicherheitsmaßnahmen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1396</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Python ausnutzen, um Dateien zu manipulieren und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Python ausnutzen, um Dateien zu manipulieren und Sicherheitsmaßnahmen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1396</guid>
    </item>
  </channel>
</rss>
