<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:36:26 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-18503</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-18503</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: python3, Alpaquita:25: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:25: python3&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: python3, Alpaquita:25: python3, BellSoft Hardened Containers:23: python3, BellSoft Hardened Containers:25: python3&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-18503</guid>
    </item>
    <item>
      <title>BIT-libpython-2026-18503 — Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libpython-2026-18503</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;Attacker-controlled CSV samples can trigger super-linear 
regular-expression work during dialect sniffing and consume significant 
CPU when applications pass unbounded input to csv.Sniffer.sniff().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;Attacker-controlled CSV samples can trigger super-linear 
regular-expression work during dialect sniffing and consume significant 
CPU when applications pass unbounded input to csv.Sniffer.sniff().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libpython-2026-18503</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0994 — Une vulnérabilité a été découverte dans CPython. Elle permet à un attaquant de provoquer un déni de service à distance.</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0994</link>
      <description>certfr-2026-avi-0994</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0994</guid>
    </item>
    <item>
      <title>EUVD-2026-351831</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-351831</link>
      <description>EUVD-2026-351831</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-351831</guid>
    </item>
    <item>
      <title>fkie_cve-2026-18503</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-18503</link>
      <description>&lt;p&gt;Attacker-controlled CSV samples can trigger super-linear 
regular-expression work during dialect sniffing and consume significant 
CPU when applications pass unbounded input to csv.Sniffer.sniff().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Attacker-controlled CSV samples can trigger super-linear 
regular-expression work during dialect sniffing and consume significant 
CPU when applications pass unbounded input to csv.Sniffer.sniff().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-18503</guid>
    </item>
    <item>
      <title>GHSA-2345-wr3r-cxf2</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2345-wr3r-cxf2</link>
      <description>&lt;p&gt;Attacker-controlled CSV samples can trigger super-linear 
regular-expression work during dialect sniffing and consume significant 
CPU when applications pass unbounded input to csv.Sniffer.sniff().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Attacker-controlled CSV samples can trigger super-linear 
regular-expression work during dialect sniffing and consume significant 
CPU when applications pass unbounded input to csv.Sniffer.sniff().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2345-wr3r-cxf2</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-18503 — Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-18503</link>
      <description>msrc_CVE-2026-18503</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-18503</guid>
    </item>
    <item>
      <title>OESA-2026-4009 — python3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4009</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.(CVE-2026-15806)&lt;/p&gt;
&lt;p&gt;The &amp;amp;qu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.(CVE-2026-15806)&lt;/p&gt;
&lt;p&gt;The &amp;amp;qu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4009</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11817-1 — python313-3.13.15-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11817-1</link>
      <description>&lt;p&gt;python313-3.13.15-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-3.13.15-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11817-1</guid>
    </item>
    <item>
      <title>RHSA-2026:54534 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:54534</link>
      <description>&lt;p&gt;python: Python Tarfile: Unexpected file ownership when extracting hardlinks python: Python: Performance degradation in XML processing due to quadratic time complexity python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory python: Python tarfile module: Denial of Service via improper EOF handling in streaming mode python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations python: Python: Denial of Service via super-linear regular expression work in csv.Sniffer.sniff()&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: Python Tarfile: Unexpected file ownership when extracting hardlinks python: Python: Performance degradation in XML processing due to quadratic time complexity python: cpython: CPython: tarfile extraction filter bypass allows escaping the destination directory python: Python tarfile module: Denial of Service via improper EOF handling in streaming mode python: Python: CPU Denial of Service in HTML parser via repeated unterminated markup declarations python: Python: Denial of Service via super-linear regular expression work in csv.Sniffer.sniff()&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:54534</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:4411-1 — Security update for python</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:4411-1</link>
      <description>&lt;p&gt;Security update for python&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:4411-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-18503</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18503</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.8 and 7 more&lt;/p&gt;
&lt;p&gt;Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.8 and 7 more&lt;/p&gt;
&lt;p&gt;Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-18503</guid>
    </item>
  </channel>
</rss>
