The Python Software Foundation maintains a focused vulnerability footprint centered on the Python interpreter and related libraries such as Paramiko, which are foundational components widely embedded across application stacks and infrastructure tooling. The observed weakness classes cluster around link-resolution and file-access issues that reflect the interaction between Python's file handling and operating system semantics. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Python Software Foundation over time
Of all the CVEs published by Python Software Foundation as a CNA, 0.0% affect products that Python Software Foundation develops as a vendor.
Of all the CVEs published that affect products developed by Python Software Foundation, 0.0% are self-published by Python Software Foundation as a CNA.
Signals from CVEs in this vendor scope (315 CVEs).
315 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0224HIGH OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to | Jun 5, 2014 | 7.4 | 83 | NO | YES |
CVE-2016-2183HIGH The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which mak | Sep 1, 2016 | 7.5 | 77 | NO | NO |
CVE-2018-25032HIGH zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. | Mar 25, 2022 | 7.5 | 56 | NO | NO |
CVE-2014-4650CRITICAL The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script sou | Feb 20, 2020 | 9.8 | 51 | NO | YES |
CVE-2008-4864HIGH Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary co | Nov 1, 2008 | 7.5 | 46 | NO | YES |
CVE-2007-4559CRITICAL Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files | Aug 28, 2007 | 9.8 | 46 | NO | NO |
CVE-2008-1721HIGH Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers in | Apr 10, 2008 | 7.5 | 44 | NO | YES |
CVE-2021-3177CRITICAL Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-poi | Jan 19, 2021 | 9.8 | 42 | NO | NO |
CVE-2018-1000802CRITICAL Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shut | Sep 18, 2018 | 9.8 | 41 | NO | NO |
CVE-2014-1912HIGH Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to exec | Mar 1, 2014 | 7.5 | 39 | NO | YES |
Signals from CVEs in this vendor scope (315 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Python Software Foundation.
Media articles that mention a CVE ID that affects a product developed by Python Software Foundation — matched by CVE ID, not by vendor name.