<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:39:36 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:23342 — Moderate: python3.9 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:23342</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python-unversioned-command, AlmaLinux:9: python3, AlmaLinux:9: python3-debug, AlmaLinux:9: python3-devel, AlmaLinux:9: python3-idle, AlmaLinux:9: python3-libs, AlmaLinux:9: python3-test, AlmaLinux:9: python3-tkinter&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Invalid value for OpenSSL API may cause Buffer over-read when NPN is used (CVE-2024-5642)
  * cpython: Python HTMLParser quadratic complexity (CVE-2025-6069)
  * cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked (CVE-2025-8291)
  * python: Quadratic complexity in os.path.expandvars() with user-controlled template (CVE-2025-6075)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python-unversioned-command, AlmaLinux:9: python3, AlmaLinux:9: python3-debug, AlmaLinux:9: python3-devel, AlmaLinux:9: python3-idle, AlmaLinux:9: python3-libs, AlmaLinux:9: python3-test, AlmaLinux:9: python3-tkinter&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* python: Invalid value for OpenSSL API may cause Buffer over-read when NPN is used (CVE-2024-5642)
  * cpython: Python HTMLParser quadratic complexity (CVE-2025-6069)
  * cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked (CVE-2025-8291)
  * python: Quadratic complexity in os.path.expandvars() with user-controlled template (CVE-2025-6075)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:23342</guid>
    </item>
    <item>
      <title>bdu:2025-11082</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-11082</link>
      <description>bdu:2025-11082</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-11082</guid>
    </item>
    <item>
      <title>BIT-libpython-2025-6069 — HTMLParser quadratic complexity when processing malformed inputs</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libpython-2025-6069</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libpython-2025-6069</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0622 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</link>
      <description>certfr-2025-avi-0622</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0622</guid>
    </item>
    <item>
      <title>EUVD-2026-343266</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343266</link>
      <description>EUVD-2026-343266</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343266</guid>
    </item>
    <item>
      <title>fkie_cve-2025-6069</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-6069</link>
      <description>&lt;p&gt;The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-6069</guid>
    </item>
    <item>
      <title>GHSA-j5cc-6rx8-ff96</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j5cc-6rx8-ff96</link>
      <description>&lt;p&gt;The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j5cc-6rx8-ff96</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-6069 — HTMLParser quadratic complexity when processing malformed inputs</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-6069</link>
      <description>msrc_CVE-2025-6069</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-6069</guid>
    </item>
    <item>
      <title>OESA-2025-1758 — jython security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1758</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: jython, openEuler:24.03-LTS-SP2: jython, openEuler:20.03-LTS-SP4: jython, openEuler:22.03-LTS-SP3: jython, openEuler:22.03-LTS-SP4: jython, openEuler:24.03-LTS: jython&lt;/p&gt;
&lt;p&gt;Jython is an implementation of the high-level, dynamic, object-oriented language Python seamlessly integrated with the Java platform. The predecessor to Jython, JPython, is certified as 100% Pure Java. Jython is freely available for both commercial and non-commercial use and is distributed with source code. Jython is complementary to Java and is especially suited for the following tasks: Embedded scripting - Java programmers can add the Jython libraries to their system to allow end users to write simple or complicated scripts that add functionality to the application. Interactive experimentation - Jython provides an interactive interpreter that can be used to interact with Java packages or with running Java applications. This allows programmers to experiment and debug any Java system using Jython. Rapid application development - Python programs are typically 2-10X shorter than the equivalent Java program. This translates directly to increased programmer productivity. The seamless interaction between Python and Java allows developers to freely mix the two languages both during development and in shipping products.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Python is an open source, object-oriented programming language from the Python Foundation. This language has the characteristics of scalability, supporting modules and packages, and supporting multiple platforms.
 There is a security vulnerability in Python that originates from the secondary complexity problem when handling specially crafted ma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: jython, openEuler:24.03-LTS-SP2: jython, openEuler:20.03-LTS-SP4: jython, openEuler:22.03-LTS-SP3: jython, openEuler:22.03-LTS-SP4: jython, openEuler:24.03-LTS: jython&lt;/p&gt;
&lt;p&gt;Jython is an implementation of the high-level, dynamic, object-oriented language Python seamlessly integrated with the Java platform. The predecessor to Jython, JPython, is certified as 100% Pure Java. Jython is freely available for both commercial and non-commercial use and is distributed with source code. Jython is complementary to Java and is especially suited for the following tasks: Embedded scripting - Java programmers can add the Jython libraries to their system to allow end users to write simple or complicated scripts that add functionality to the application. Interactive experimentation - Jython provides an interactive interpreter that can be used to interact with Java packages or with running Java applications. This allows programmers to experiment and debug any Java system using Jython. Rapid application development - Python programs are typically 2-10X shorter than the equivalent Java program. This translates directly to increased programmer productivity. The seamless interaction between Python and Java allows developers to freely mix the two languages both during development and in shipping products.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Python is an open source, object-oriented programming language from the Python Foundation. This language has the characteristics of scalability, supporting modules and packages, and supporting multiple platforms.
 There is a security vulnerability in Python that originates from the secondary complexity problem when handling specially crafted ma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1758</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15285-1 — python310-3.10.18-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15285-1</link>
      <description>&lt;p&gt;python310-3.10.18-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-3.10.18-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15285-1</guid>
    </item>
    <item>
      <title>RHSA-2026:0414 — Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:0414</link>
      <description>&lt;p&gt;python: Invalid value for OpenSSL API may cause Buffer over-read when NPN is used systemd-coredump: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump cpython: Python HTMLParser quadratic complexity python: Quadratic complexity in os.path.expandvars() with user-controlled template cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked libxslt: libxml2: Inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications qs: qs: Denial of Service via improper input validation in array parsing tar: Tar path traversal firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing django: Potential partial directory-traversal via archive.extract() openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand Django: Django: Algorithmic complexity in XML Deserializer leads to denial of service libpng: LIBPNG buffer overflow glob: glob: Command Injection Vulnerability via Malicious Filenames libpng: LIBPNG heap buffer overflow node-forge: node-forge ASN.1 Unbounded Recursion libpng: LIBPNG out-of-bounds read in png_image_read_composite urllib3: urlli…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: Invalid value for OpenSSL API may cause Buffer over-read when NPN is used systemd-coredump: race condition that allows a local attacker to crash a SUID program and gain read access to the resulting core dump cpython: Python HTMLParser quadratic complexity python: Quadratic complexity in os.path.expandvars() with user-controlled template cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked libxslt: libxml2: Inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications qs: qs: Denial of Service via improper input validation in array parsing tar: Tar path traversal firefox: thunderbird: expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing django: Potential partial directory-traversal via archive.extract() openssh: OpenSSH: Control characters in usernames can lead to code execution via ProxyCommand openssh: OpenSSH: Null character in ssh:// URI can lead to code execution via ProxyCommand Django: Django: Algorithmic complexity in XML Deserializer leads to denial of service libpng: LIBPNG buffer overflow glob: glob: Command Injection Vulnerability via Malicious Filenames libpng: LIBPNG heap buffer overflow node-forge: node-forge ASN.1 Unbounded Recursion libpng: LIBPNG out-of-bounds read in png_image_read_composite urllib3: urlli…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:0414</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:02232-1 — Security update for python39</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:02232-1</link>
      <description>&lt;p&gt;Security update for python39&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python39&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:02232-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-6069</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6069</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:16.04:LTS: jython, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:18.04:LTS: jython, Ubuntu:Pro:18.04:LTS: python3.7 and 14 more&lt;/p&gt;
&lt;p&gt;The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:16.04:LTS: jython, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:18.04:LTS: jython, Ubuntu:Pro:18.04:LTS: python3.7 and 14 more&lt;/p&gt;
&lt;p&gt;The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-6069</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1470 — Python (CPython): Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1470</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Python ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Python ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1470</guid>
    </item>
  </channel>
</rss>
