CVE Tools

Cpython

76 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Cpython, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Cpython CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Cpython CVEs per month
MonthCVEs
2024-101
2024-111
2024-121
2025-011
2025-022
2025-030
2025-040
2025-051
2025-066
2025-071
2025-080
2025-090
2025-102
2025-111
2025-123
2026-018
2026-020
2026-036
2026-048
2026-052
2026-069
2026-072
2026-085
2026-092

Severity

How the 76 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical35%
  • High2444%
  • Medium2444%
  • Low47%

Latest CVEs

The 15 most recently published vulnerabilities affecting Cpython.

  1. CVE-2026-82049tarfile extraction filters allow file modification and content disclosure via hard link to symlink—
  2. CVE-2026-87910tarfile hardlink fallback ignores custom extraction filter rejection via None—
  3. CVE-2026-15310zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits—
  4. CVE-2026-19672tarfile extraction filter bypass allows creation of directories outside the destination—
  5. CVE-2026-15806`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching—
  6. CVE-2026-17084stringprep.map_table_b2() deviates from RFC 3454 Table B.2—
  7. CVE-2026-18503Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()—
  8. CVE-2026-6879Quadratic Behavior in xml.etree.ElementPath Index Predicates—
  9. CVE-2026-15308Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations7.5
  10. CVE-2026-4360Tarfile.extract() doesn't fully respect filter parameter5.3
  11. CVE-2026-11972tarfile opened in streaming mode mishandles EOF—
  12. CVE-2026-0864Configuration Injection via Carriage Return (\r) in write() method5.5
  13. CVE-2026-11940tarfile extraction filter bypass allows escaping the destination directory—
  14. BDU:2026-08551Уязвимость функции ast_for_if_stmt() интерпретатора языка программирования Python (CPython), связанная с ошибками разыменования указателей, позволяющая нарушителю вызвать отказ в обслуживании5.5
  15. CVE-2026-12003CPython >3.11 Insecure Input Validation resulting in privilege escalation—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store