<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:12:46 +0000</lastBuildDate>
    <item>
      <title>BIT-libpython-2026-12003 — CPython &gt;3.11 Insecure Input Validation resulting in privilege escalation</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libpython-2026-12003</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;To allow builds of Python to be run from an in-tree layout (rather than
an installed file layout), the VPATH variable is defined at build time
and used to locate certain landmarks - specifically,
Modules/setup.local. When this landmark is found relative to VPATH
relative to the executable, Python assumes it is running in a source
tree and generates a different default sys.path. This code remains in
release builds, so that release-ready builds can be built in-tree.&lt;/p&gt;
&lt;p&gt;On Windows, since builds are written to &amp;#39;PCbuild/&amp;#39;, the value of
VPATH is set to &amp;#39;..\..&amp;#39;, which results in a landmark of
&amp;#39;..\..\Modules\setup.local&amp;#39;. This path is outside the install directory
of Python, and may have different permissions, potentially allowing a
low-privilege user to create the landmark and an alternative `Lib`
folder that will be discovered by an otherwise restricted install.&lt;/p&gt;
&lt;p&gt;Such a setup occurs with the legacy default install location for all
users (in the now superseded EXE installer), due to how Windows allows
all users to create folders in the root directory of their OS drive.&lt;/p&gt;
&lt;p&gt;Our recommended mitigation on Windows is to migrate away from the
legacy installer and use the new [Python install
manager](https://www.python.org/downloads/latest/pymanager/) to install
for the current user. Installs where the directory two levels above the
Python installation directory have equivalent permissions are unaffected
(in general, a per-user install cannot be modified at all by other
users, removing any es…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;To allow builds of Python to be run from an in-tree layout (rather than
an installed file layout), the VPATH variable is defined at build time
and used to locate certain landmarks - specifically,
Modules/setup.local. When this landmark is found relative to VPATH
relative to the executable, Python assumes it is running in a source
tree and generates a different default sys.path. This code remains in
release builds, so that release-ready builds can be built in-tree.&lt;/p&gt;
&lt;p&gt;On Windows, since builds are written to &amp;#39;PCbuild/&amp;#39;, the value of
VPATH is set to &amp;#39;..\..&amp;#39;, which results in a landmark of
&amp;#39;..\..\Modules\setup.local&amp;#39;. This path is outside the install directory
of Python, and may have different permissions, potentially allowing a
low-privilege user to create the landmark and an alternative `Lib`
folder that will be discovered by an otherwise restricted install.&lt;/p&gt;
&lt;p&gt;Such a setup occurs with the legacy default install location for all
users (in the now superseded EXE installer), due to how Windows allows
all users to create folders in the root directory of their OS drive.&lt;/p&gt;
&lt;p&gt;Our recommended mitigation on Windows is to migrate away from the
legacy installer and use the new [Python install
manager](https://www.python.org/downloads/latest/pymanager/) to install
for the current user. Installs where the directory two levels above the
Python installation directory have equivalent permissions are unaffected
(in general, a per-user install cannot be modified at all by other
users, removing any es…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libpython-2026-12003</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0790 — Une vulnérabilité a été découverte dans CPython pour Windows. Elle permet à un attaquant de provoquer une atteinte à la…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0790</link>
      <description>certfr-2026-avi-0790</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0790</guid>
    </item>
    <item>
      <title>EUVD-2026-351834</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351834</link>
      <description>EUVD-2026-351834</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351834</guid>
    </item>
    <item>
      <title>fkie_cve-2026-12003</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-12003</link>
      <description>&lt;p&gt;To allow builds of Python to be run from an in-tree layout (rather than
an installed file layout), the VPATH variable is defined at build time
and used to locate certain landmarks - specifically,
Modules/setup.local. When this landmark is found relative to VPATH
relative to the executable, Python assumes it is running in a source
tree and generates a different default sys.path. This code remains in
release builds, so that release-ready builds can be built in-tree.&lt;/p&gt;
&lt;p&gt;On Windows, since builds are written to &amp;#39;PCbuild/&amp;#39;, the value of
VPATH is set to &amp;#39;..\..&amp;#39;, which results in a landmark of
&amp;#39;..\..\Modules\setup.local&amp;#39;. This path is outside the install directory
of Python, and may have different permissions, potentially allowing a
low-privilege user to create the landmark and an alternative `Lib`
folder that will be discovered by an otherwise restricted install.&lt;/p&gt;
&lt;p&gt;Such a setup occurs with the legacy default install location for all
users (in the now superseded EXE installer), due to how Windows allows
all users to create folders in the root directory of their OS drive.&lt;/p&gt;
&lt;p&gt;Our recommended mitigation on Windows is to migrate away from the
legacy installer and use the new [Python install
manager](https://www.python.org/downloads/latest/pymanager/) to install
for the current user. Installs where the directory two levels above the
Python installation directory have equivalent permissions are unaffected
(in general, a per-user install cannot be modified at all by other
users, removing any es…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;To allow builds of Python to be run from an in-tree layout (rather than
an installed file layout), the VPATH variable is defined at build time
and used to locate certain landmarks - specifically,
Modules/setup.local. When this landmark is found relative to VPATH
relative to the executable, Python assumes it is running in a source
tree and generates a different default sys.path. This code remains in
release builds, so that release-ready builds can be built in-tree.&lt;/p&gt;
&lt;p&gt;On Windows, since builds are written to &amp;#39;PCbuild/&amp;#39;, the value of
VPATH is set to &amp;#39;..\..&amp;#39;, which results in a landmark of
&amp;#39;..\..\Modules\setup.local&amp;#39;. This path is outside the install directory
of Python, and may have different permissions, potentially allowing a
low-privilege user to create the landmark and an alternative `Lib`
folder that will be discovered by an otherwise restricted install.&lt;/p&gt;
&lt;p&gt;Such a setup occurs with the legacy default install location for all
users (in the now superseded EXE installer), due to how Windows allows
all users to create folders in the root directory of their OS drive.&lt;/p&gt;
&lt;p&gt;Our recommended mitigation on Windows is to migrate away from the
legacy installer and use the new [Python install
manager](https://www.python.org/downloads/latest/pymanager/) to install
for the current user. Installs where the directory two levels above the
Python installation directory have equivalent permissions are unaffected
(in general, a per-user install cannot be modified at all by other
users, removing any es…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-12003</guid>
    </item>
    <item>
      <title>GHSA-2wqx-fp26-qh5v</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2wqx-fp26-qh5v</link>
      <description>&lt;p&gt;To allow builds of Python to be run from an in-tree layout (rather than
an installed file layout), the VPATH variable is defined at build time
and used to locate certain landmarks - specifically,
Modules/setup.local. When this landmark is found relative to VPATH
relative to the executable, Python assumes it is running in a source
tree and generates a different default sys.path. This code remains in
release builds, so that release-ready builds can be built in-tree.&lt;/p&gt;
&lt;p&gt;On Windows, since builds are written to &amp;#39;PCbuild/&amp;#39;, the value of
VPATH is set to &amp;#39;..\..&amp;#39;, which results in a landmark of
&amp;#39;..\..\Modules\setup.local&amp;#39;. This path is outside the install directory
of Python, and may have different permissions, potentially allowing a
low-privilege user to create the landmark and an alternative `Lib`
folder that will be discovered by an otherwise restricted install.&lt;/p&gt;
&lt;p&gt;Such a setup occurs with the legacy default install location for all
users (in the now superseded EXE installer), due to how Windows allows
all users to create folders in the root directory of their OS drive.&lt;/p&gt;
&lt;p&gt;Our recommended mitigation on Windows is to migrate away from the
legacy installer and use the new [Python install
manager](https://www.python.org/downloads/latest/pymanager/) to install
for the current user. Installs where the directory two levels above the
Python installation directory have equivalent permissions are unaffected
(in general, a per-user install cannot be modified at all by other
users, removing any es…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;To allow builds of Python to be run from an in-tree layout (rather than
an installed file layout), the VPATH variable is defined at build time
and used to locate certain landmarks - specifically,
Modules/setup.local. When this landmark is found relative to VPATH
relative to the executable, Python assumes it is running in a source
tree and generates a different default sys.path. This code remains in
release builds, so that release-ready builds can be built in-tree.&lt;/p&gt;
&lt;p&gt;On Windows, since builds are written to &amp;#39;PCbuild/&amp;#39;, the value of
VPATH is set to &amp;#39;..\..&amp;#39;, which results in a landmark of
&amp;#39;..\..\Modules\setup.local&amp;#39;. This path is outside the install directory
of Python, and may have different permissions, potentially allowing a
low-privilege user to create the landmark and an alternative `Lib`
folder that will be discovered by an otherwise restricted install.&lt;/p&gt;
&lt;p&gt;Such a setup occurs with the legacy default install location for all
users (in the now superseded EXE installer), due to how Windows allows
all users to create folders in the root directory of their OS drive.&lt;/p&gt;
&lt;p&gt;Our recommended mitigation on Windows is to migrate away from the
legacy installer and use the new [Python install
manager](https://www.python.org/downloads/latest/pymanager/) to install
for the current user. Installs where the directory two levels above the
Python installation directory have equivalent permissions are unaffected
(in general, a per-user install cannot be modified at all by other
users, removing any es…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2wqx-fp26-qh5v</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-12003 — CPython &gt;3.11 Insecure Input Validation resulting in privilege escalation</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-12003</link>
      <description>msrc_CVE-2026-12003</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-12003</guid>
    </item>
    <item>
      <title>OESA-2026-3070 — python3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3070</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;When using the &amp;amp;quot;configparser&amp;amp;quot; module to write configuration files
containing multi-line text values with carriage return characters (\r) the
resulting file could be injected with unexpected keys and values if the
attacker controls the written value.(CVE-2026-0864)&lt;/p&gt;
&lt;p&gt;To allow builds of Python to be run from an in-tree layout (rather than
an installed file layout), the VPATH variable is defined at build time
and used to locate certain landmarks - specifically,
Modules/setup.local. When this landmark is found relative to VPATH
relative to the executable, Python assumes it is running in a source
tree and generates a different default sys.path. This code remains in
release builds, so that release-ready builds can be built in-tree.&lt;/p&gt;
&lt;p&gt;On Windows, since builds are written to &amp;amp;apos;PCbuild/&amp;amp;apos;, the value of
VPATH is set to &amp;amp;apos;..\..&amp;amp;apos;, which results in a landmark of
&amp;amp;apos;..\..\Modules\setup.local&amp;amp;apos;. This path is outside the install directo…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;When using the &amp;amp;quot;configparser&amp;amp;quot; module to write configuration files
containing multi-line text values with carriage return characters (\r) the
resulting file could be injected with unexpected keys and values if the
attacker controls the written value.(CVE-2026-0864)&lt;/p&gt;
&lt;p&gt;To allow builds of Python to be run from an in-tree layout (rather than
an installed file layout), the VPATH variable is defined at build time
and used to locate certain landmarks - specifically,
Modules/setup.local. When this landmark is found relative to VPATH
relative to the executable, Python assumes it is running in a source
tree and generates a different default sys.path. This code remains in
release builds, so that release-ready builds can be built in-tree.&lt;/p&gt;
&lt;p&gt;On Windows, since builds are written to &amp;amp;apos;PCbuild/&amp;amp;apos;, the value of
VPATH is set to &amp;amp;apos;..\..&amp;amp;apos;, which results in a landmark of
&amp;amp;apos;..\..\Modules\setup.local&amp;amp;apos;. This path is outside the install directo…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3070</guid>
    </item>
    <item>
      <title>RHSA-2026:67572 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:67572</link>
      <description>&lt;p&gt;python: Python unicodedata: Denial of Service due to excessive CPU consumption python: Python/Expat: Denial of Service via crafted XML document python: Python: FTP connection redirection via ftpcp() function bypass python: Python: Denial of Service via out-of-bounds write in BZ2 decompression python: Python: Privilege escalation due to insecure VPATH handling in Windows legacy installers python: Python tarfile module: Security filter bypass allows arbitrary file write&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: Python unicodedata: Denial of Service due to excessive CPU consumption python: Python/Expat: Denial of Service via crafted XML document python: Python: FTP connection redirection via ftpcp() function bypass python: Python: Denial of Service via out-of-bounds write in BZ2 decompression python: Python: Privilege escalation due to insecure VPATH handling in Windows legacy installers python: Python tarfile module: Security filter bypass allows arbitrary file write&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:67572</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-12003</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-12003</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: cython, Ubuntu:18.04:LTS: cython, Ubuntu:20.04:LTS: cython, Ubuntu:22.04:LTS: cython, Ubuntu:24.04:LTS: cython, Ubuntu:25.10: cython, Ubuntu:26.04:LTS: cython&lt;/p&gt;
&lt;p&gt;To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree. On Windows, since builds are written to &amp;#39;PCbuild/&amp;#39;, the value of VPATH is set to &amp;#39;..\..&amp;#39;, which results in a landmark of &amp;#39;..\..\Modules\setup.local&amp;#39;. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install. Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive. Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escal…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: cython, Ubuntu:18.04:LTS: cython, Ubuntu:20.04:LTS: cython, Ubuntu:22.04:LTS: cython, Ubuntu:24.04:LTS: cython, Ubuntu:25.10: cython, Ubuntu:26.04:LTS: cython&lt;/p&gt;
&lt;p&gt;To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree. On Windows, since builds are written to &amp;#39;PCbuild/&amp;#39;, the value of VPATH is set to &amp;#39;..\..&amp;#39;, which results in a landmark of &amp;#39;..\..\Modules\setup.local&amp;#39;. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install. Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive. Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.python.org/downloads/latest/pymanager/) to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escal…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-12003</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1971 — CPython: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1971</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CPython ausnutzen, um Dateien zu manipulieren und um einen Denial-of-Service-Zustand auszulösen&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CPython ausnutzen, um Dateien zu manipulieren und um einen Denial-of-Service-Zustand auszulösen&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1971</guid>
    </item>
  </channel>
</rss>
