Pocoo develops a narrowly scoped set of widely used Python libraries, with a durable vulnerability signal centered on template-handling and internationalization components such as Jinja2 and Babel. The observed weaknesses cluster around code-injection and path-traversal flaws, reflecting the parsing and code-generation demands inherent to template engines and locale processing. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pocoo over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-8341CRITICAL An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, rende | Feb 15, 2019 | 9.8 | 63 | NO | YES |
CVE-2021-42771HIGH Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution. | Oct 20, 2021 | 7.8 | 26 | NO | NO |
CVE-2014-0012MEDIUM FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a use | May 19, 2014 | 4.4 | 18 | NO | NO |
CVE-2014-1402MEDIUM The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a cra | May 19, 2014 | 4.4 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pocoo.
Media articles that mention a CVE ID that affects a product developed by Pocoo — matched by CVE ID, not by vendor name.