Python Software Foundation
Self-Reporting Analysis
Of all the CVEs published by Python Software Foundation as a CNA, 0.0% affect products that Python Software Foundation develops as a vendor.
Of all the CVEs published that affect products developed by Python Software Foundation, 0.0% are self-published by Python Software Foundation as a CNA.
Trends Over Time
The number and severity of CVEs published by Python Software Foundation over time
Top CVEs
All CVEs published by Python Software Foundation as a CNA, regardless of affected vendor or product.
71 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-15308HIGH The incremental HTML parser (html.parser.HTMLParser) allows for CPU
denial-of-service through repeated unterminated markup declarations when
processing uncontrolled data. | Jul 9, 2026 | 7.5 | 38 | NO | NO |
CVE-2026-11972HIGH When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer. | Jun 23, 2026 | 8.2 | 37 | NO | NO |
CVE-2026-11940HIGH tarfile.extractall() with the 'data' or 'tar'
filter could be bypassed by a crafted archive where a hardlink
references a symlink stored at a deeper name than the hardlink itself | Jun 23, 2026 | 7.8 | 36 | NO | NO |
CVE-2026-9669HIGH bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could | Jun 8, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-6100HIGH Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompressi | Apr 13, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-7210HIGH `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFu | May 11, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-4786HIGH Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands | Apr 13, 2026 | 7.1 | 31 | NO | NO |
CVE-2026-7774MEDIUM tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extr | Jun 4, 2026 | 6.9 | 30 | NO | NO |
CVE-2026-8328MEDIUM The ftpcp() function in Lib/ftplib.py was not updated when
CVE-2021-4189 was fixed. While makepasv() was patched to replace
server-supplied PASV host addresses with the actual pe | May 13, 2026 | 5.9 | 30 | NO | NO |
CVE-2026-3298HIGH The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an ou | Apr 21, 2026 | 8.8 | 30 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (71 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Python Software Foundation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Python Software Foundation as a CNA — matched by CVE ID, not by organization name.