<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 19:15:06 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-1502 — HTTP client proxy tunnel headers not validated for CR/LF</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-1502</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Python Software Foundation CPython&lt;/p&gt;
&lt;p&gt;CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Python Software Foundation CPython&lt;/p&gt;
&lt;p&gt;CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-1502</guid>
    </item>
    <item>
      <title>USN-8509-1 — python3.10, python3.12, python3.14 vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8509-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: python3.10, Ubuntu:24.04:LTS: python3.12, Ubuntu:26.04:LTS: python3.14&lt;/p&gt;
&lt;p&gt;It was discovered that Python incorrectly normalized paths in the tarfile
module. An attacker could possibly use this issue to bypass path
restrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (CVE-2025-13462)&lt;/p&gt;
&lt;p&gt;It was discovered that Python&amp;#39;s HTMLParser incorrectly handled certain
malformed HTML input. An attacker could possibly use this issue to cause
Python to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-69534)&lt;/p&gt;
&lt;p&gt;It was discovered that Python&amp;#39;s email module incorrectly quoted newlines
in headers. An attacker could possibly use this issue to inject arbitrary
email headers. This issue only affected Ubuntu 22.04 LTS and Ubuntu
24.04 LTS. (CVE-2026-1299)&lt;/p&gt;
&lt;p&gt;It was discovered that Python&amp;#39;s http.client module did not properly
sanitize carriage return and linefeed characters when handling HTTP
CONNECT tunnel request headers. An attacker could possibly use this issue
to inject arbitrary HTTP headers. (CVE-2026-1502)&lt;/p&gt;
&lt;p&gt;It was discovered that Python&amp;#39;s importlib module did not generate an
audit event when loading legacy .pyc files. An attacker could possibly
use this issue to bypass auditing mechanisms. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-2297)&lt;/p&gt;
&lt;p&gt;It was discovered that Python&amp;#39;s unicodedata.normalize() function had
incorrect algorithmic complexity. An attacker could possibly use this
issue to cause Python to consume excessive resources, leading to a denial
of…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: python3.10, Ubuntu:24.04:LTS: python3.12, Ubuntu:26.04:LTS: python3.14&lt;/p&gt;
&lt;p&gt;It was discovered that Python incorrectly normalized paths in the tarfile
module. An attacker could possibly use this issue to bypass path
restrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (CVE-2025-13462)&lt;/p&gt;
&lt;p&gt;It was discovered that Python&amp;#39;s HTMLParser incorrectly handled certain
malformed HTML input. An attacker could possibly use this issue to cause
Python to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-69534)&lt;/p&gt;
&lt;p&gt;It was discovered that Python&amp;#39;s email module incorrectly quoted newlines
in headers. An attacker could possibly use this issue to inject arbitrary
email headers. This issue only affected Ubuntu 22.04 LTS and Ubuntu
24.04 LTS. (CVE-2026-1299)&lt;/p&gt;
&lt;p&gt;It was discovered that Python&amp;#39;s http.client module did not properly
sanitize carriage return and linefeed characters when handling HTTP
CONNECT tunnel request headers. An attacker could possibly use this issue
to inject arbitrary HTTP headers. (CVE-2026-1502)&lt;/p&gt;
&lt;p&gt;It was discovered that Python&amp;#39;s importlib module did not generate an
audit event when loading legacy .pyc files. An attacker could possibly
use this issue to bypass auditing mechanisms. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-2297)&lt;/p&gt;
&lt;p&gt;It was discovered that Python&amp;#39;s unicodedata.normalize() function had
incorrect algorithmic complexity. An attacker could possibly use this
issue to cause Python to consume excessive resources, leading to a denial
of…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8509-1</guid>
    </item>
  </channel>
</rss>
