<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 10:03:39 +0000</lastBuildDate>
    <item>
      <title>BIT-libpython-2026-87910 — tarfile hardlink fallback ignores custom extraction filter rejection via None</title>
      <link>https://cve.radiocsirt.org/vuln/bit-libpython-2026-87910</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;When tarfile extracts a link on a system that doesn&amp;#39;t support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: libpython&lt;/p&gt;
&lt;p&gt;When tarfile extracts a link on a system that doesn&amp;#39;t support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-libpython-2026-87910</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1167 — De multiples vulnérabilités ont été découvertes dans Python. Certaines d'entre elles permettent à un attaquant de provo…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1167</link>
      <description>certfr-2026-avi-1167</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1167</guid>
    </item>
    <item>
      <title>EUVD-2026-382002</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-382002</link>
      <description>EUVD-2026-382002</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-382002</guid>
    </item>
    <item>
      <title>fkie_cve-2026-87910</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-87910</link>
      <description>&lt;p&gt;When tarfile extracts a link on a system that doesn&amp;#39;t support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When tarfile extracts a link on a system that doesn&amp;#39;t support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-87910</guid>
    </item>
    <item>
      <title>GHSA-rj44-3777-mh5x</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rj44-3777-mh5x</link>
      <description>&lt;p&gt;When tarfile extracts a link on a system that doesn&amp;#39;t support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;When tarfile extracts a link on a system that doesn&amp;#39;t support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rj44-3777-mh5x</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-87910 — tarfile hardlink fallback ignores custom extraction filter rejection via None</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-87910</link>
      <description>msrc_CVE-2026-87910</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-87910</guid>
    </item>
    <item>
      <title>OESA-2026-4009 — python3 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4009</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.(CVE-2026-15806)&lt;/p&gt;
&lt;p&gt;The &amp;amp;qu…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python3&lt;/p&gt;
&lt;p&gt;Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.(CVE-2026-15806)&lt;/p&gt;
&lt;p&gt;The &amp;amp;qu…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4009</guid>
    </item>
    <item>
      <title>RHSA-2026:67572 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:67572</link>
      <description>&lt;p&gt;python: Python unicodedata: Denial of Service due to excessive CPU consumption python: Python/Expat: Denial of Service via crafted XML document python: Python: FTP connection redirection via ftpcp() function bypass python: Python: Denial of Service via out-of-bounds write in BZ2 decompression python: Python: Privilege escalation due to insecure VPATH handling in Windows legacy installers python: Python tarfile module: Security filter bypass allows arbitrary file write&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python: Python unicodedata: Denial of Service due to excessive CPU consumption python: Python/Expat: Denial of Service via crafted XML document python: Python: FTP connection redirection via ftpcp() function bypass python: Python: Denial of Service via out-of-bounds write in BZ2 decompression python: Python: Privilege escalation due to insecure VPATH handling in Windows legacy installers python: Python tarfile module: Security filter bypass allows arbitrary file write&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:67572</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-87910</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-87910</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.8 and 11 more&lt;/p&gt;
&lt;p&gt;When tarfile extracts a link on a system that doesn&amp;#39;t support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: python2.7, Ubuntu:Pro:14.04:LTS: python3.4, Ubuntu:Pro:14.04:LTS: python3.5, Ubuntu:Pro:16.04:LTS: python2.7, Ubuntu:Pro:16.04:LTS: python3.5, Ubuntu:Pro:18.04:LTS: python2.7, Ubuntu:Pro:18.04:LTS: python3.6, Ubuntu:Pro:18.04:LTS: python3.7, Ubuntu:Pro:18.04:LTS: python3.8, Ubuntu:Pro:20.04:LTS: python3.8 and 11 more&lt;/p&gt;
&lt;p&gt;When tarfile extracts a link on a system that doesn&amp;#39;t support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-87910</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3335 — CPython: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3335</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in CPython ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in CPython ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3335</guid>
    </item>
  </channel>
</rss>
