Python Software Foundation

First CVE: Oct 25, 2023Active for: 3 years
71
CVEs Published
More CVEs Published than 66% of tracked CNAs
17.8
Avg CVEs / Year
More Avg CVEs / Year than 65% of tracked CNAs
6.1
Avg CVSS Score
Higher Avg CVSS Score than 10% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Python Software Foundation as a CNA, 0.0% affect products that Python Software Foundation develops as a vendor.

100.0%
Self-reported: 0Third-party: 71

Of all the CVEs published that affect products developed by Python Software Foundation, 0.0% are self-published by Python Software Foundation as a CNA.

100.0%
Self-published: 0Published by other CNAs: 3

Trends Over Time

The number and severity of CVEs published by Python Software Foundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2023
2 years ago
Most Recent CVE
Jul 9, 2026
15 days ago

Top CVEs

All CVEs published by Python Software Foundation as a CNA, regardless of affected vendor or product.

71 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
Jul 9, 20267.538NONO
When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.
Jun 23, 20268.237NONO
tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself
Jun 23, 20267.836NONO
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could
Jun 8, 20268.235NONO
Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompressi
Apr 13, 20268.134NONO
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFu
May 11, 20267.532NONO
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands
Apr 13, 20267.131NONO
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extr
Jun 4, 20266.930NONO
The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual pe
May 13, 20265.930NONO
The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an ou
Apr 21, 20268.830NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA71 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCriticalNone
Attack Vector
Local19 (26.8%)
Network52 (73.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low60 (84.5%)
High11 (15.5%)
Unknown0 (0.0%)
User Interaction
None53 (74.6%)
Unknown0 (0.0%)
Required7 (9.9%)
Privileges Required
Low16 (22.5%)
High9 (12.7%)
None46 (64.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (71 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Python Software Foundation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Python Software Foundation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs