Python
168 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Python, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Python CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 1 |
| 2024-12 | 1 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 2 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 1 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 4 |
| 2026-01 | 7 |
| 2026-02 | 0 |
| 2026-03 | 4 |
| 2026-04 | 3 |
| 2026-05 | 1 |
| 2026-06 | 2 |
| 2026-07 | 1 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 168 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical19
- High66
- Medium75
- Low8
Latest CVEs
The 15 most recently published vulnerabilities affecting Python.
- CVE-2026-15308Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations7.5
- CVE-2026-4360Tarfile.extract() doesn't fully respect filter parameter5.3
- CVE-2026-0864Configuration Injection via Carriage Return (\r) in write() method5.5
- CVE-2026-7210The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection7.5
- CVE-2026-3087shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs7.5
- CVE-2026-41140Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.48.7
- CVE-2026-6019BaseCookie.js_output() does not neutralize embedded characters6.1
- CVE-2026-4519webbrowser.open() allows leading dashes in URLs3.3
- CVE-2026-4224Stack overflow parsing XML with deeply nested DTD content models7.5
- CVE-2026-3644Incomplete control character validation in http.cookies7.5
- CVE-2025-13462tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling3.3
- CVE-2026-1299email BytesGenerator header injection due to unquoted newlines7.1
- CVE-2025-12781base64.b64decode() always accepts "+/" characters, despite setting altchars5.3
- CVE-2026-0672Header injection in http.cookies.Morsel7.1
- CVE-2025-15367POP3 command injection in user-controlled commands5.5
Product grouping is registry-driven, with AI assist and human review. How it works