<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:38:07 +0000</lastBuildDate>
    <item>
      <title>BIT-libpython-2026-17084 — stringprep.map_table_b2() deviates from RFC 3454 Table B.2</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libpython-2026-17084</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;The &amp;#34;stringprep&amp;#34; module didn&amp;#39;t process characters from RFC 3454 tables 
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used 
instead of the specified Unicode 3.2.0. This behavior would cause 
mismatches when processing domain names using IDNA 2003 (the &amp;#34;idna&amp;#34; 
codec) and the in_table_b2() function of the &amp;#34;stringprep&amp;#34; module. This 
only affects domain names containing characters that were not previously
 registered or had their Unicode attributes such as case-folding 
behavior updated since Unicode 3.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;The &amp;#34;stringprep&amp;#34; module didn&amp;#39;t process characters from RFC 3454 tables 
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used 
instead of the specified Unicode 3.2.0. This behavior would cause 
mismatches when processing domain names using IDNA 2003 (the &amp;#34;idna&amp;#34; 
codec) and the in_table_b2() function of the &amp;#34;stringprep&amp;#34; module. This 
only affects domain names containing characters that were not previously
 registered or had their Unicode attributes such as case-folding 
behavior updated since Unicode 3.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libpython-2026-17084</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1044 — De multiples vulnérabilités ont été découvertes dans Python. Elles permettent à un attaquant de provoquer une atteinte…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1044</link>
      <description>certfr-2026-avi-1044</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1044</guid>
    </item>
    <item>
      <title>EUVD-2026-382008</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-382008</link>
      <description>EUVD-2026-382008</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-382008</guid>
    </item>
    <item>
      <title>fkie_cve-2026-17084</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-17084</link>
      <description>&lt;p&gt;The &amp;#34;stringprep&amp;#34; module didn&amp;#39;t process characters from RFC 3454 tables 
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used 
instead of the specified Unicode 3.2.0. This behavior would cause 
mismatches when processing domain names using IDNA 2003 (the &amp;#34;idna&amp;#34; 
codec) and the in_table_b2() function of the &amp;#34;stringprep&amp;#34; module. This 
only affects domain names containing characters that were not previously
 registered or had their Unicode attributes such as case-folding 
behavior updated since Unicode 3.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The &amp;#34;stringprep&amp;#34; module didn&amp;#39;t process characters from RFC 3454 tables 
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used 
instead of the specified Unicode 3.2.0. This behavior would cause 
mismatches when processing domain names using IDNA 2003 (the &amp;#34;idna&amp;#34; 
codec) and the in_table_b2() function of the &amp;#34;stringprep&amp;#34; module. This 
only affects domain names containing characters that were not previously
 registered or had their Unicode attributes such as case-folding 
behavior updated since Unicode 3.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-17084</guid>
    </item>
    <item>
      <title>GHSA-w246-x8qv-r8f5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w246-x8qv-r8f5</link>
      <description>&lt;p&gt;The &amp;#34;stringprep&amp;#34; module didn&amp;#39;t process characters from RFC 3454 tables 
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used 
instead of the specified Unicode 3.2.0. This behavior would cause 
mismatches when processing domain names using IDNA 2003 (the &amp;#34;idna&amp;#34; 
codec) and the in_table_b2() function of the &amp;#34;stringprep&amp;#34; module. This 
only affects domain names containing characters that were not previously
 registered or had their Unicode attributes such as case-folding 
behavior updated since Unicode 3.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The &amp;#34;stringprep&amp;#34; module didn&amp;#39;t process characters from RFC 3454 tables 
B.2 or B.3 correctly: the latest Unicode codepoint attributes were used 
instead of the specified Unicode 3.2.0. This behavior would cause 
mismatches when processing domain names using IDNA 2003 (the &amp;#34;idna&amp;#34; 
codec) and the in_table_b2() function of the &amp;#34;stringprep&amp;#34; module. This 
only affects domain names containing characters that were not previously
 registered or had their Unicode attributes such as case-folding 
behavior updated since Unicode 3.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w246-x8qv-r8f5</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-17084 — stringprep.map_table_b2() deviates from RFC 3454 Table B.2</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-17084</link>
      <description>msrc_CVE-2026-17084</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-17084</guid>
    </item>
    <item>
      <title>OESA-2026-4009 — python3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4009</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.(CVE-2026-15806)&lt;/p&gt;
&lt;p&gt;The &amp;amp;qu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.(CVE-2026-15806)&lt;/p&gt;
&lt;p&gt;The &amp;amp;qu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4009</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11817-1 — python313-3.13.15-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11817-1</link>
      <description>&lt;p&gt;python313-3.13.15-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-3.13.15-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11817-1</guid>
    </item>
    <item>
      <title>RHSA-2026:65505 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:65505</link>
      <description>&lt;p&gt;python: Python: Information disclosure due to incorrect URL scheme matching python: Python stringprep module: Incorrect domain name processing breaks IDNA interoperability python: Python tarfile module: Directory traversal allows creation of empty directories outside extraction destination python: Python tarfile module: File modification and content disclosure via crafted archives&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: Python: Information disclosure due to incorrect URL scheme matching python: Python stringprep module: Incorrect domain name processing breaks IDNA interoperability python: Python tarfile module: Directory traversal allows creation of empty directories outside extraction destination python: Python tarfile module: File modification and content disclosure via crafted archives&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:65505</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23743-1 — Security update for python311</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23743-1</link>
      <description>&lt;p&gt;Security update for python311&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python311&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23743-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-17084</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-17084</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.8 and 7 more&lt;/p&gt;
&lt;p&gt;The &amp;#34;stringprep&amp;#34; module didn&amp;#39;t process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the &amp;#34;idna&amp;#34; codec) and the in_table_b2() function of the &amp;#34;stringprep&amp;#34; module. This only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.8 and 7 more&lt;/p&gt;
&lt;p&gt;The &amp;#34;stringprep&amp;#34; module didn&amp;#39;t process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the &amp;#34;idna&amp;#34; codec) and the in_table_b2() function of the &amp;#34;stringprep&amp;#34; module. This only affects domain names containing characters that were not previously  registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-17084</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2924 — CPython: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2924</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in CPython ausnutzen, um Informationen offenzulegen und um nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in CPython ausnutzen, um Informationen offenzulegen und um nicht näher spezifizierte Auswirkungen zu erzielen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2924</guid>
    </item>
  </channel>
</rss>
