<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:51:18 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:10779 — Moderate: python3:3.6.8 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:10779</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: platform-python, AlmaLinux:8: platform-python-debug, AlmaLinux:8: platform-python-devel, AlmaLinux:8: python3-idle, AlmaLinux:8: python3-libs, AlmaLinux:8: python3-test, AlmaLinux:8: python3-tkinter&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Virtual environment (venv) activation scripts don&amp;#39;t quote paths (CVE-2024-9287)
  * python: Improper validation of IPv6 and IPvFuture addresses (CVE-2024-11168)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: platform-python, AlmaLinux:8: platform-python-debug, AlmaLinux:8: platform-python-devel, AlmaLinux:8: python3-idle, AlmaLinux:8: python3-libs, AlmaLinux:8: python3-test, AlmaLinux:8: python3-tkinter&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Virtual environment (venv) activation scripts don&amp;#39;t quote paths (CVE-2024-9287)
  * python: Improper validation of IPv6 and IPvFuture addresses (CVE-2024-11168)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:10779</guid>
    </item>
    <item>
      <title>bdu:2025-03332</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-03332</link>
      <description>bdu:2025-03332</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-03332</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-9287</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-9287</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:stream: python3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:stream: python3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-9287</guid>
    </item>
    <item>
      <title>BIT-libpython-2024-9287 — Virtual environment (venv) activation scripts don't quote paths</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libpython-2024-9287</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment &amp;#34;activation&amp;#34; scripts (ie &amp;#34;source venv/bin/activate&amp;#34;). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren&amp;#39;t activated before being used (ie &amp;#34;./venv/bin/python&amp;#34;) are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment &amp;#34;activation&amp;#34; scripts (ie &amp;#34;source venv/bin/activate&amp;#34;). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren&amp;#39;t activated before being used (ie &amp;#34;./venv/bin/python&amp;#34;) are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libpython-2024-9287</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0422 — De multiples vulnérabilités ont été découvertes dans IBM QRadar SIEM. Certaines d'entre elles permettent à un attaquant…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0422</link>
      <description>certfr-2025-avi-0422</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0422</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-CI66802 — Security fixes for CVE-2015-2104, CVE-2020-8908, CVE-2021-21295, CVE-2021-21409, CVE-2021-37136, CVE-2022-1471, CVE-202…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: cassandra-fips&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the cassandra-fips package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ci66802</guid>
    </item>
    <item>
      <title>EUVD-2026-258733</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258733</link>
      <description>EUVD-2026-258733</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258733</guid>
    </item>
    <item>
      <title>fkie_cve-2024-9287</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-9287</link>
      <description>&lt;p&gt;A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment &amp;#34;activation&amp;#34; scripts (ie &amp;#34;source venv/bin/activate&amp;#34;). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren&amp;#39;t activated before being used (ie &amp;#34;./venv/bin/python&amp;#34;) are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment &amp;#34;activation&amp;#34; scripts (ie &amp;#34;source venv/bin/activate&amp;#34;). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren&amp;#39;t activated before being used (ie &amp;#34;./venv/bin/python&amp;#34;) are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-9287</guid>
    </item>
    <item>
      <title>GHSA-grqq-hcc7-crmr</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-grqq-hcc7-crmr</link>
      <description>&lt;p&gt;A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment &amp;#34;activation&amp;#34; scripts (ie &amp;#34;source venv/bin/activate&amp;#34;). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren&amp;#39;t activated before being used (ie &amp;#34;./venv/bin/python&amp;#34;) are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment &amp;#34;activation&amp;#34; scripts (ie &amp;#34;source venv/bin/activate&amp;#34;). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren&amp;#39;t activated before being used (ie &amp;#34;./venv/bin/python&amp;#34;) are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-grqq-hcc7-crmr</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-9287 — Virtual environment (venv) activation scripts don't quote paths</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-9287</link>
      <description>msrc_CVE-2024-9287</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-9287</guid>
    </item>
    <item>
      <title>OESA-2024-2481 — python3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2481</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment &amp;amp;quot;activation&amp;amp;quot; scripts (ie &amp;amp;quot;source venv/bin/activate&amp;amp;quot;). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren&amp;amp;apos;t activated before being used (ie &amp;amp;quot;./venv/bin/python&amp;amp;quot;) are not affected.(CVE-2024-9287)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&#13;
&#13;
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment &amp;amp;quot;activation&amp;amp;quot; scripts (ie &amp;amp;quot;source venv/bin/activate&amp;amp;quot;). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren&amp;amp;apos;t activated before being used (ie &amp;amp;quot;./venv/bin/python&amp;amp;quot;) are not affected.(CVE-2024-9287)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2481</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14426-1 — python310-virtualenv-20.26.6-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14426-1</link>
      <description>&lt;p&gt;python310-virtualenv-20.26.6-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-virtualenv-20.26.6-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14426-1</guid>
    </item>
    <item>
      <title>RHBA-2025:6294 — Red Hat Bug Fix Advisory: python3.12 bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2025:6294</link>
      <description>&lt;p&gt;python: cpython: tarfile: ReDos via excessive backtracking while parsing header values python: Virtual environment (venv) activation scripts don&amp;#39;t quote paths python: Unbounded memory buffering in SelectorSocketTransport.writelines() python: cpython: URL parser allowed square brackets in domain names&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: cpython: tarfile: ReDos via excessive backtracking while parsing header values python: Virtual environment (venv) activation scripts don&amp;#39;t quote paths python: Unbounded memory buffering in SelectorSocketTransport.writelines() python: cpython: URL parser allowed square brackets in domain names&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2025:6294</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:3760-1 — Security update for python3</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:3760-1</link>
      <description>&lt;p&gt;Security update for python3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:3760-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-9287</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-9287</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:20.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.9, Ubuntu:22.04:LTS: python3.10, Ubuntu:Pro:22.04:LTS: python3.11 and 1 more&lt;/p&gt;
&lt;p&gt;A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment &amp;#34;activation&amp;#34; scripts (ie &amp;#34;source venv/bin/activate&amp;#34;). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren&amp;#39;t activated before being used (ie &amp;#34;./venv/bin/python&amp;#34;) are not affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:20.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.9, Ubuntu:22.04:LTS: python3.10, Ubuntu:Pro:22.04:LTS: python3.11 and 1 more&lt;/p&gt;
&lt;p&gt;A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment &amp;#34;activation&amp;#34; scripts (ie &amp;#34;source venv/bin/activate&amp;#34;). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren&amp;#39;t activated before being used (ie &amp;#34;./venv/bin/python&amp;#34;) are not affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-9287</guid>
    </item>
    <item>
      <title>VDE-2025-053 — Phoenix Contact: Multiple Vulnerabilities in PLCnext Firmware</title>
      <link>https://cve.radiocsirt.org/vuln/vde-2025-053</link>
      <description>&lt;p&gt;Coreutils: heap overflow in split --line-bytes with very long lines Unprivileged overlay + shiftfs read access Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file SSL_select_next_proto buffer overread Remote Code Execution in pypa/setuptools&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Coreutils: heap overflow in split --line-bytes with very long lines Unprivileged overlay + shiftfs read access Nano: running `chmod` and `chown` on the filename allows malicious user to replace the emergency file with a malicious symlink to a root-owned file SSL_select_next_proto buffer overread Remote Code Execution in pypa/setuptools&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/vde-2025-053</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-3270 — Python: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3270</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Python und Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in Python und Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3270</guid>
    </item>
  </channel>
</rss>
