← Back

Python

python

268 CVEs • 30 products

Products (30)

Click to collapse
Toggle
Python
python
Pillow
pillow
Urllib3
urllib3
Requests
requests
Setuptools
setuptools
Keyring
keyring
Pyxdg
pyxdg
Typed Ast
typed_ast
Black
black
Virtualenv
virtualenv
Beaker
beaker
Rply
rply
Rsa
rsa
Tgcaptcha2
tgcaptcha2
Hpack
hpack
Hyper
hyper
Openpyxl
openpyxl
Tablib
tablib
Pypiserver
pypiserver
Python Gnupg
python-gnupg
Novajoin
novajoin
Pyxml
pyxml
Py Bcrypt
py-bcrypt
Jw.util
jw.util
Pybluemonday
pybluemonday
Tkvideoplayer
tkvideoplayer
Pypi
pypi
Pymanager
pymanager
Cpython
cpython

CVEs (268)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
7Canonical
DebianFedoraproject+4 more
8Debian Linux
FedoraHci Storage Node+5 more
Jun 17, 2026
Sep 27, 2020
N/A· v4
7.2 HIGH· v3
6.4 MEDIUM· v2
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF cont...Show more
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.Show less
2Netapp
Python
2Max Data
Python
Jun 17, 2026
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected.
7Canonical
DebianFedoraproject+4 more
8Active Iq Unified Manager
Cloud Volumes Ontap MediatorDebian Linux+5 more
Jun 17, 2026
Jul 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
2Netapp
Python
2Python
Snapcenter
Jun 17, 2026
Jul 4, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs...Show more
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for python3.dll loading (after Py_SetPath has been used). NOTE: this issue CANNOT occur when using python.exe from a standard (non-embedded) Python installation on Windows.Show less
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jun 25, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jun 25, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jun 25, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jun 25, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraPillow+1 more
Jun 17, 2026
Jun 25, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
4Fedoraproject
OpensuseOracle+1 more
4Enterprise Manager Ops Center
FedoraLeap+1 more
Jun 17, 2026
Jun 18, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by t...Show more
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2.Show less
1Python
1Jw.util
Jun 17, 2026
May 22, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary...Show more
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resulting in OS command execution, because safe_load is not used.Show less
1Python
1Python
Nov 21, 2024
Mar 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
1Python
1Urllib3
Jun 17, 2026
Mar 6, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array cont...Show more
The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percent_encodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percent_encodings were deduplicated, the time to compute _encode_invalid_chars would be O(kN), where k is at most 484 ((10+6*2)^2).Show less
2Python
Redhat
3Enterprise Linux
PythonSoftware Collections
Nov 21, 2024
Feb 20, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal...Show more
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.Show less
3Canonical
NetappPython
3Active Iq Unified Manager
PythonUbuntu Linux
Jun 17, 2026
Feb 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Jan 30, 2020
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of...Show more
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.Show less
1Python
1Python
Jun 17, 2026
Jan 28, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and...Show more
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's copy. Windows 8 and later are unaffected.Show less
2Fedoraproject
Python
2Fedora
Py Bcrypt
Nov 21, 2024
Jan 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be ov...Show more
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraPillow+1 more
Jun 17, 2026
Jan 5, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results...Show more
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraPillow+1 more
Jun 17, 2026
Jan 3, 2020
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.