<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:40:25 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:23323 — Moderate: python3.12 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:23323</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3.12, AlmaLinux:9: python3.12-debug, AlmaLinux:9: python3.12-devel, AlmaLinux:9: python3.12-idle, AlmaLinux:9: python3.12-libs, AlmaLinux:9: python3.12-test, AlmaLinux:9: python3.12-tkinter&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked (CVE-2025-8291)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3.12, AlmaLinux:9: python3.12-debug, AlmaLinux:9: python3.12-devel, AlmaLinux:9: python3.12-idle, AlmaLinux:9: python3.12-libs, AlmaLinux:9: python3.12-test, AlmaLinux:9: python3.12-tkinter&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked (CVE-2025-8291)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:23323</guid>
    </item>
    <item>
      <title>bdu:2026-00313</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00313</link>
      <description>bdu:2026-00313</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00313</guid>
    </item>
    <item>
      <title>BIT-libpython-2025-8291 — ZIP64 End of Central Directory (EOCD) Locator record offset not checked</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libpython-2025-8291</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;The &amp;#39;zipfile&amp;#39; module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the &amp;#39;zipfile&amp;#39; module
compared to other ZIP implementations.&lt;/p&gt;
&lt;p&gt;Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;The &amp;#39;zipfile&amp;#39; module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the &amp;#39;zipfile&amp;#39; module
compared to other ZIP implementations.&lt;/p&gt;
&lt;p&gt;Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libpython-2025-8291</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0851 — Une vulnérabilité a été découverte dans Python. Elle permet à un attaquant de provoquer un problème de sécurité non spé…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0851</link>
      <description>certfr-2025-avi-0851</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0851</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-JY81919 — Security fixes in python3 3.14.0-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-jy81919</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: python3&lt;/p&gt;
&lt;p&gt;Package python3 version 3.14.0-r0 fixes 1 vulnerabilities: CVE-2025-8291&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: python3&lt;/p&gt;
&lt;p&gt;Package python3 version 3.14.0-r0 fixes 1 vulnerabilities: CVE-2025-8291&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-jy81919</guid>
    </item>
    <item>
      <title>EUVD-2026-343262</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343262</link>
      <description>EUVD-2026-343262</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343262</guid>
    </item>
    <item>
      <title>fkie_cve-2025-8291</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-8291</link>
      <description>&lt;p&gt;The &amp;#39;zipfile&amp;#39; module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the &amp;#39;zipfile&amp;#39; module
compared to other ZIP implementations.&lt;/p&gt;
&lt;p&gt;Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The &amp;#39;zipfile&amp;#39; module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the &amp;#39;zipfile&amp;#39; module
compared to other ZIP implementations.&lt;/p&gt;
&lt;p&gt;Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-8291</guid>
    </item>
    <item>
      <title>GHSA-49g5-f6qw-8mm7</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-49g5-f6qw-8mm7</link>
      <description>&lt;p&gt;The &amp;#39;zipfile&amp;#39; module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the &amp;#39;zipfile&amp;#39; module
compared to other ZIP implementations.&lt;/p&gt;
&lt;p&gt;Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The &amp;#39;zipfile&amp;#39; module would not check the validity of the ZIP64 End of
Central Directory (EOCD) Locator record offset value would not be used to
locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be
assumed to be the previous record in the ZIP archive. This could be abused
to create ZIP archives that are handled differently by the &amp;#39;zipfile&amp;#39; module
compared to other ZIP implementations.&lt;/p&gt;
&lt;p&gt;Remediation maintains this behavior, but checks that the offset specified
in the ZIP64 EOCD Locator record matches the expected value.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-49g5-f6qw-8mm7</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-8291 — ZIP64 End of Central Directory (EOCD) Locator record offset not checked</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-8291</link>
      <description>msrc_CVE-2025-8291</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-8291</guid>
    </item>
    <item>
      <title>OESA-2025-2574 — python3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2574</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment  activation  scripts (ie  source venv/bin/activate ). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren t activated before being used (ie  ./venv/bin/python ) are not affected.(CVE-2024-9287)&lt;/p&gt;
&lt;p&gt;The  zipfile  module in CPython would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value. This offset value was not used to locate the ZIP64 EOCD record; instead, the ZIP64 EOCD record was assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the  zipfile  module compared to other ZI…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment  activation  scripts (ie  source venv/bin/activate ). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren t activated before being used (ie  ./venv/bin/python ) are not affected.(CVE-2024-9287)&lt;/p&gt;
&lt;p&gt;The  zipfile  module in CPython would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value. This offset value was not used to locate the ZIP64 EOCD record; instead, the ZIP64 EOCD record was assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the  zipfile  module compared to other ZI…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2574</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15742-1 — python312-3.12.12-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15742-1</link>
      <description>&lt;p&gt;python312-3.12.12-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python312-3.12.12-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15742-1</guid>
    </item>
    <item>
      <title>RHSA-2026:0353 — Red Hat Security Advisory: python3.12 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:0353</link>
      <description>&lt;p&gt;cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cpython: python: Python zipfile End of Central Directory (EOCD) Locator record offset not checked&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:0353</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:21199-1 — Security update for python311</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:21199-1</link>
      <description>&lt;p&gt;Security update for python311&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python311&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:21199-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-8291</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8291</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.8 and 8 more&lt;/p&gt;
&lt;p&gt;The &amp;#39;zipfile&amp;#39; module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the &amp;#39;zipfile&amp;#39; module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.8 and 8 more&lt;/p&gt;
&lt;p&gt;The &amp;#39;zipfile&amp;#39; module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the &amp;#39;zipfile&amp;#39; module compared to other ZIP implementations. Remediation maintains this behavior, but checks that the offset specified in the ZIP64 EOCD Locator record matches the expected value.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-8291</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2230 — Python (CPython Zipfile Module): Schwachstelle ermöglicht Manipulation von Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2230</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle im zipfile-Modul von CPython ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle im zipfile-Modul von CPython ausnutzen, um Dateien zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2230</guid>
    </item>
  </channel>
</rss>
