<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:03:36 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:5962 — Moderate: python39:3.9 and python39-devel:3.9 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:5962</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python39, AlmaLinux:8: python39-Cython, AlmaLinux:8: python39-PyMySQL, AlmaLinux:8: python39-attrs, AlmaLinux:8: python39-cffi, AlmaLinux:8: python39-chardet, AlmaLinux:8: python39-cryptography, AlmaLinux:8: python39-debug, AlmaLinux:8: python39-devel, AlmaLinux:8: python39-idle and 39 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: incorrect IPv4 and IPv6 private ranges (CVE-2024-4032)
* pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools (CVE-2024-6345)
* cpython: python: email module doesn&amp;#39;t properly quotes newlines in email headers, allowing header injection (CVE-2024-6923)
* python: cpython: From NVD collector (CVE-2024-8088)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python39, AlmaLinux:8: python39-Cython, AlmaLinux:8: python39-PyMySQL, AlmaLinux:8: python39-attrs, AlmaLinux:8: python39-cffi, AlmaLinux:8: python39-chardet, AlmaLinux:8: python39-cryptography, AlmaLinux:8: python39-debug, AlmaLinux:8: python39-devel, AlmaLinux:8: python39-idle and 39 more&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: incorrect IPv4 and IPv6 private ranges (CVE-2024-4032)
* pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools (CVE-2024-6345)
* cpython: python: email module doesn&amp;#39;t properly quotes newlines in email headers, allowing header injection (CVE-2024-6923)
* python: cpython: From NVD collector (CVE-2024-8088)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:5962</guid>
    </item>
    <item>
      <title>bdu:2024-06863</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-06863</link>
      <description>bdu:2024-06863</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-06863</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-8088</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-8088</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:stream: python3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:stream: python3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-8088</guid>
    </item>
    <item>
      <title>BIT-libpython-2024-8088 — Infinite loop when iterating over zip archive entry names from zipfile.Path</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libpython-2024-8088</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;There is a HIGH severity vulnerability affecting the CPython &amp;#34;zipfile&amp;#34;
module affecting &amp;#34;zipfile.Path&amp;#34;. Note that the more common API &amp;#34;zipfile.ZipFile&amp;#34; class is unaffected.&lt;/p&gt;
&lt;p&gt;When iterating over names of entries in a zip archive (for example, methods
of &amp;#34;zipfile.Path&amp;#34; like &amp;#34;namelist()&amp;#34;, &amp;#34;iterdir()&amp;#34;, etc)
the process can be put into an infinite loop with a maliciously crafted
zip archive. This defect applies when reading only metadata or extracting
the contents of the zip archive. Programs that are not handling
user-controlled zip archives are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;There is a HIGH severity vulnerability affecting the CPython &amp;#34;zipfile&amp;#34;
module affecting &amp;#34;zipfile.Path&amp;#34;. Note that the more common API &amp;#34;zipfile.ZipFile&amp;#34; class is unaffected.&lt;/p&gt;
&lt;p&gt;When iterating over names of entries in a zip archive (for example, methods
of &amp;#34;zipfile.Path&amp;#34; like &amp;#34;namelist()&amp;#34;, &amp;#34;iterdir()&amp;#34;, etc)
the process can be put into an infinite loop with a maliciously crafted
zip archive. This defect applies when reading only metadata or extracting
the contents of the zip archive. Programs that are not handling
user-controlled zip archives are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libpython-2024-8088</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0958 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0958</link>
      <description>certfr-2024-avi-0958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0958</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CQ39979 — Security fixes in cassandra 5.0.6-r2</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-cq39979</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra&lt;/p&gt;
&lt;p&gt;Package cassandra version 5.0.6-r2 fixes 26 vulnerabilities: ghsa-72hv-8253-57qq, ghsa-pr98-23f8-jwxv, ghsa-25qh-j22f-pwp8, ghsa-6v67-2wr5-gvf4, ghsa-qqpg-mvqg-649v...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra&lt;/p&gt;
&lt;p&gt;Package cassandra version 5.0.6-r2 fixes 26 vulnerabilities: ghsa-72hv-8253-57qq, ghsa-pr98-23f8-jwxv, ghsa-25qh-j22f-pwp8, ghsa-6v67-2wr5-gvf4, ghsa-qqpg-mvqg-649v...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-cq39979</guid>
    </item>
    <item>
      <title>EUVD-2026-258725</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258725</link>
      <description>EUVD-2026-258725</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258725</guid>
    </item>
    <item>
      <title>fkie_cve-2024-8088</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-8088</link>
      <description>&lt;p&gt;There is a HIGH severity vulnerability affecting the CPython &amp;#34;zipfile&amp;#34;
module affecting &amp;#34;zipfile.Path&amp;#34;. Note that the more common API &amp;#34;zipfile.ZipFile&amp;#34; class is unaffected.&lt;/p&gt;
&lt;p&gt;When iterating over names of entries in a zip archive (for example, methods
of &amp;#34;zipfile.Path&amp;#34; like &amp;#34;namelist()&amp;#34;, &amp;#34;iterdir()&amp;#34;, etc)
the process can be put into an infinite loop with a maliciously crafted
zip archive. This defect applies when reading only metadata or extracting
the contents of the zip archive. Programs that are not handling
user-controlled zip archives are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a HIGH severity vulnerability affecting the CPython &amp;#34;zipfile&amp;#34;
module affecting &amp;#34;zipfile.Path&amp;#34;. Note that the more common API &amp;#34;zipfile.ZipFile&amp;#34; class is unaffected.&lt;/p&gt;
&lt;p&gt;When iterating over names of entries in a zip archive (for example, methods
of &amp;#34;zipfile.Path&amp;#34; like &amp;#34;namelist()&amp;#34;, &amp;#34;iterdir()&amp;#34;, etc)
the process can be put into an infinite loop with a maliciously crafted
zip archive. This defect applies when reading only metadata or extracting
the contents of the zip archive. Programs that are not handling
user-controlled zip archives are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-8088</guid>
    </item>
    <item>
      <title>GHSA-q98g-hxg3-268c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q98g-hxg3-268c</link>
      <description>&lt;p&gt;There is a HIGH severity vulnerability affecting the CPython &amp;#34;zipfile&amp;#34;
module.&lt;/p&gt;
&lt;p&gt;When iterating over names of entries in a zip archive (for example, methods
of &amp;#34;zipfile.ZipFile&amp;#34; like &amp;#34;namelist()&amp;#34;, &amp;#34;iterdir()&amp;#34;, &amp;#34;extractall()&amp;#34;, etc)
the process can be put into an infinite loop with a maliciously crafted
zip archive. This defect applies when reading only metadata or extracting
the contents of the zip archive. Programs that are not handling
user-controlled zip archives are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;There is a HIGH severity vulnerability affecting the CPython &amp;#34;zipfile&amp;#34;
module.&lt;/p&gt;
&lt;p&gt;When iterating over names of entries in a zip archive (for example, methods
of &amp;#34;zipfile.ZipFile&amp;#34; like &amp;#34;namelist()&amp;#34;, &amp;#34;iterdir()&amp;#34;, &amp;#34;extractall()&amp;#34;, etc)
the process can be put into an infinite loop with a maliciously crafted
zip archive. This defect applies when reading only metadata or extracting
the contents of the zip archive. Programs that are not handling
user-controlled zip archives are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q98g-hxg3-268c</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-8088 — Infinite loop when iterating over zip archive entry names from zipfile.Path</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-8088</link>
      <description>msrc_CVE-2024-8088</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-8088</guid>
    </item>
    <item>
      <title>OESA-2024-2116 — python3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2116</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&#13;
&#13;
There is a MEDIUM severity vulnerability affecting CPython.&#13;
&#13;
The 
email module didn’t properly quote newlines for email headers when 
serializing an email message allowing for header injection when an email
 is serialized.(CVE-2024-6923)&#13;
&#13;
There is a LOW severity vulnerability affecting CPython, specifically the
&amp;amp;apos;http.cookies&amp;amp;apos; standard library module.&lt;/p&gt;
&lt;p&gt;When parsing cookies that contained backslashes for quoted characters in
the cookie value, the parser would use an algorithm with quadratic
complexity, resulting in excess CPU resources being used while parsing the
value.(CVE-2024-7592)&#13;
&#13;
There is a HIGH severity vulnerability affecting the CPython &amp;amp;quot;zipfile&amp;amp;quot;
module affecting &amp;amp;quot;zipfile.Path&amp;amp;quot;. Note that the more common API &amp;amp;quot;zipfile.ZipFile&amp;amp;quot; class is unaffected.&#13;
&#13;
&#13;
&#13;
&#13;
&#13;
When iterating over names of entries in a zip archive (for example, methods
of &amp;amp;quot;zipfile.Path&amp;amp;quot; like &amp;amp;quot;namelist()&amp;amp;quot;, &amp;amp;quot;…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&#13;
&#13;
There is a MEDIUM severity vulnerability affecting CPython.&#13;
&#13;
The 
email module didn’t properly quote newlines for email headers when 
serializing an email message allowing for header injection when an email
 is serialized.(CVE-2024-6923)&#13;
&#13;
There is a LOW severity vulnerability affecting CPython, specifically the
&amp;amp;apos;http.cookies&amp;amp;apos; standard library module.&lt;/p&gt;
&lt;p&gt;When parsing cookies that contained backslashes for quoted characters in
the cookie value, the parser would use an algorithm with quadratic
complexity, resulting in excess CPU resources being used while parsing the
value.(CVE-2024-7592)&#13;
&#13;
There is a HIGH severity vulnerability affecting the CPython &amp;amp;quot;zipfile&amp;amp;quot;
module affecting &amp;amp;quot;zipfile.Path&amp;amp;quot;. Note that the more common API &amp;amp;quot;zipfile.ZipFile&amp;amp;quot; class is unaffected.&#13;
&#13;
&#13;
&#13;
&#13;
&#13;
When iterating over names of entries in a zip archive (for example, methods
of &amp;amp;quot;zipfile.Path&amp;amp;quot; like &amp;amp;quot;namelist()&amp;amp;quot;, &amp;amp;quot;…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2116</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14296-1 — python38-3.8.19-8.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14296-1</link>
      <description>&lt;p&gt;python38-3.8.19-8.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python38-3.8.19-8.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14296-1</guid>
    </item>
    <item>
      <title>RHSA-2024:5962 — Red Hat Security Advisory: python39:3.9 and python39-devel:3.9 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:5962</link>
      <description>&lt;p&gt;python: incorrect IPv4 and IPv6 private ranges pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools cpython: python: email module doesn&amp;#39;t properly quotes newlines in email headers, allowing header injection python: cpython: Iterating over a malicious ZIP file may lead to Denial of Service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: incorrect IPv4 and IPv6 private ranges pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools cpython: python: email module doesn&amp;#39;t properly quotes newlines in email headers, allowing header injection python: cpython: Iterating over a malicious ZIP file may lead to Denial of Service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:5962</guid>
    </item>
    <item>
      <title>SUSE-EL-9-CLIENT-TOOLS-2024-4029 — Security update for SUSE Manager Salt Bundle</title>
      <link>https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2024-4029</link>
      <description>&lt;p&gt;Security update for SUSE Manager Salt Bundle&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for SUSE Manager Salt Bundle&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2024-4029</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-8088</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-8088</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:20.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.9, Ubuntu:22.04:LTS: python3.10, Ubuntu:Pro:22.04:LTS: python3.11, Ubuntu:24.04:LTS: python3.12&lt;/p&gt;
&lt;p&gt;There is a HIGH severity vulnerability affecting the CPython &amp;#34;zipfile&amp;#34; module affecting &amp;#34;zipfile.Path&amp;#34;. Note that the more common API &amp;#34;zipfile.ZipFile&amp;#34; class is unaffected. When iterating over names of entries in a zip archive (for example, methods of &amp;#34;zipfile.Path&amp;#34; like &amp;#34;namelist()&amp;#34;, &amp;#34;iterdir()&amp;#34;, etc) the process can be put into an infinite loop with a maliciously crafted zip archive. This defect applies when reading only metadata or extracting the contents of the zip archive. Programs that are not handling user-controlled zip archives are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:20.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.9, Ubuntu:22.04:LTS: python3.10, Ubuntu:Pro:22.04:LTS: python3.11, Ubuntu:24.04:LTS: python3.12&lt;/p&gt;
&lt;p&gt;There is a HIGH severity vulnerability affecting the CPython &amp;#34;zipfile&amp;#34; module affecting &amp;#34;zipfile.Path&amp;#34;. Note that the more common API &amp;#34;zipfile.ZipFile&amp;#34; class is unaffected. When iterating over names of entries in a zip archive (for example, methods of &amp;#34;zipfile.Path&amp;#34; like &amp;#34;namelist()&amp;#34;, &amp;#34;iterdir()&amp;#34;, etc) the process can be put into an infinite loop with a maliciously crafted zip archive. This defect applies when reading only metadata or extracting the contents of the zip archive. Programs that are not handling user-controlled zip archives are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-8088</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1914 — Python: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1914</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Python ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Python ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1914</guid>
    </item>
  </channel>
</rss>
