<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:07:17 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:10950 — Important: python3.12 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:10950</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3.12, AlmaLinux:8: python3.12-debug, AlmaLinux:8: python3.12-devel, AlmaLinux:8: python3.12-idle, AlmaLinux:8: python3.12-libs, AlmaLinux:8: python3.12-rpm-macros, AlmaLinux:8: python3.12-test, AlmaLinux:8: python3.12-tkinter&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing (CVE-2025-59375)
  * python: Quadratic complexity in os.path.expandvars() with user-controlled template (CVE-2025-6075)
  * cpython: Out-of-memory when loading Plist (CVE-2025-13837)
  * cpython: Header injection via newlines in data URL mediatype in Python (CVE-2025-15282)
  * cpython: Header injection in http.cookies.Morsel in Python (CVE-2026-0672)
  * cpython: CPython: Logging Bypass in Legacy .pyc File Handling (CVE-2026-2297)
  * cpython: Incomplete control character validation in http.cookies (CVE-2026-3644)
  * cpython: Stack overflow parsing XML with deeply nested DTD content models (CVE-2026-4224)
  * python: Python: HTTP header injection via CR/LF in proxy tunnel headers (CVE-2026-1502)
  * python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules (CVE-2026-6100)
  * python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API (CVE-2026-4786)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgment…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3.12, AlmaLinux:8: python3.12-debug, AlmaLinux:8: python3.12-devel, AlmaLinux:8: python3.12-idle, AlmaLinux:8: python3.12-libs, AlmaLinux:8: python3.12-rpm-macros, AlmaLinux:8: python3.12-test, AlmaLinux:8: python3.12-tkinter&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* expat: libexpat in Expat allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing (CVE-2025-59375)
  * python: Quadratic complexity in os.path.expandvars() with user-controlled template (CVE-2025-6075)
  * cpython: Out-of-memory when loading Plist (CVE-2025-13837)
  * cpython: Header injection via newlines in data URL mediatype in Python (CVE-2025-15282)
  * cpython: Header injection in http.cookies.Morsel in Python (CVE-2026-0672)
  * cpython: CPython: Logging Bypass in Legacy .pyc File Handling (CVE-2026-2297)
  * cpython: Incomplete control character validation in http.cookies (CVE-2026-3644)
  * cpython: Stack overflow parsing XML with deeply nested DTD content models (CVE-2026-4224)
  * python: Python: HTTP header injection via CR/LF in proxy tunnel headers (CVE-2026-1502)
  * python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules (CVE-2026-6100)
  * python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API (CVE-2026-4786)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgment…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:10950</guid>
    </item>
    <item>
      <title>bdu:2026-09515</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09515</link>
      <description>bdu:2026-09515</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09515</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-1502</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-1502</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: python3, Alpaquita:25: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:25: python3, BellSoft Hardened Containers:stream: python3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: python3, Alpaquita:25: python3, Alpaquita:stream: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:25: python3, BellSoft Hardened Containers:stream: python3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-1502</guid>
    </item>
    <item>
      <title>BIT-libpython-2026-1502 — HTTP client proxy tunnel headers not validated for CR/LF</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libpython-2026-1502</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libpython-2026-1502</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0426 — De multiples vulnérabilités ont été découvertes dans Python. Elles permettent à un attaquant de provoquer un contournem…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0426</link>
      <description>certfr-2026-avi-0426</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0426</guid>
    </item>
    <item>
      <title>EUVD-2026-351833</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351833</link>
      <description>EUVD-2026-351833</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351833</guid>
    </item>
    <item>
      <title>fkie_cve-2026-1502</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-1502</link>
      <description>&lt;p&gt;CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-1502</guid>
    </item>
    <item>
      <title>GHSA-hjxq-7w9q-2jw6</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hjxq-7w9q-2jw6</link>
      <description>&lt;p&gt;CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hjxq-7w9q-2jw6</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-1502 — HTTP client proxy tunnel headers not validated for CR/LF</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-1502</link>
      <description>msrc_CVE-2026-1502</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-1502</guid>
    </item>
    <item>
      <title>OESA-2026-2115 — python3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2115</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.(CVE-2026-1502)&lt;/p&gt;
&lt;p&gt;Mitgation of CVE-2026-4519 was incomplete. If the URL contained &amp;amp;quot;%action&amp;amp;quot; the mitigation could be bypassed for certain browser types the &amp;amp;quot;webbrowser.open()&amp;amp;quot; API could have commands injected into the underlying shell. See CVE-2026-4519 for details.(CVE-2026-4786)&lt;/p&gt;
&lt;p&gt;Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition.&lt;/p&gt;
&lt;p&gt;The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lz…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.(CVE-2026-1502)&lt;/p&gt;
&lt;p&gt;Mitgation of CVE-2026-4519 was incomplete. If the URL contained &amp;amp;quot;%action&amp;amp;quot; the mitigation could be bypassed for certain browser types the &amp;amp;quot;webbrowser.open()&amp;amp;quot; API could have commands injected into the underlying shell. See CVE-2026-4519 for details.(CVE-2026-4786)&lt;/p&gt;
&lt;p&gt;Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition.&lt;/p&gt;
&lt;p&gt;The vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lz…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2115</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10647-1 — python310-3.10.20-6.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10647-1</link>
      <description>&lt;p&gt;python310-3.10.20-6.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python310-3.10.20-6.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10647-1</guid>
    </item>
    <item>
      <title>RHSA-2026:10117 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10117</link>
      <description>&lt;p&gt;python: Python: HTTP header injection via CR/LF in proxy tunnel headers python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: Python: HTTP header injection via CR/LF in proxy tunnel headers python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10117</guid>
    </item>
    <item>
      <title>RLSA-2026:19176 — Important: python3.14 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:19176</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: python3.14&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cpython: wsgiref.headers.Headers allows header newline injection in Python (CVE-2026-0865)&lt;/p&gt;
&lt;p&gt;* cpython: CPython: Logging Bypass in Legacy .pyc File Handling (CVE-2026-2297)&lt;/p&gt;
&lt;p&gt;* cpython: Incomplete control character validation in http.cookies (CVE-2026-3644)&lt;/p&gt;
&lt;p&gt;* cpython: Stack overflow parsing XML with deeply nested DTD content models (CVE-2026-4224)&lt;/p&gt;
&lt;p&gt;* python: Python: Command-line option injection in webbrowser.open() via crafted URLs (CVE-2026-4519)&lt;/p&gt;
&lt;p&gt;* python: Python: HTTP header injection via CR/LF in proxy tunnel headers (CVE-2026-1502)&lt;/p&gt;
&lt;p&gt;* python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules (CVE-2026-6100)&lt;/p&gt;
&lt;p&gt;* python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API (CVE-2026-4786)&lt;/p&gt;
&lt;p&gt;* python: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. (CVE-2026-5713)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: python3.14&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cpython: wsgiref.headers.Headers allows header newline injection in Python (CVE-2026-0865)&lt;/p&gt;
&lt;p&gt;* cpython: CPython: Logging Bypass in Legacy .pyc File Handling (CVE-2026-2297)&lt;/p&gt;
&lt;p&gt;* cpython: Incomplete control character validation in http.cookies (CVE-2026-3644)&lt;/p&gt;
&lt;p&gt;* cpython: Stack overflow parsing XML with deeply nested DTD content models (CVE-2026-4224)&lt;/p&gt;
&lt;p&gt;* python: Python: Command-line option injection in webbrowser.open() via crafted URLs (CVE-2026-4519)&lt;/p&gt;
&lt;p&gt;* python: Python: HTTP header injection via CR/LF in proxy tunnel headers (CVE-2026-1502)&lt;/p&gt;
&lt;p&gt;* python: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules (CVE-2026-6100)&lt;/p&gt;
&lt;p&gt;* python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API (CVE-2026-4786)&lt;/p&gt;
&lt;p&gt;* python: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. (CVE-2026-5713)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:19176</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1818-1 — Security update for python39</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1818-1</link>
      <description>&lt;p&gt;Security update for python39&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python39&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1818-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-1502</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-1502</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:16.04:LTS: jython, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:18.04:LTS: jython, Ubuntu:Pro:18.04:LTS: python3.7 and 21 more&lt;/p&gt;
&lt;p&gt;CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:16.04:LTS: jython, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:18.04:LTS: jython, Ubuntu:Pro:18.04:LTS: python3.7 and 21 more&lt;/p&gt;
&lt;p&gt;CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-1502</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1064 — CPython: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1064</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CPython ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CPython ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1064</guid>
    </item>
  </channel>
</rss>
