Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
BIT-python-2026-87910
  • Bitnami/python
tarfile hardlink fallback ignores custom extraction filter rejection via None yesterday
  • No fix available
  • Severity - 5.7 (Medium)
BIT-python-min-2026-87910
  • Bitnami/python-min
tarfile hardlink fallback ignores custom extraction filter rejection via None yesterday
  • No fix available
  • Severity - 5.7 (Medium)
BIT-libpython-2026-87910
  • Bitnami/libpython
tarfile hardlink fallback ignores custom extraction filter rejection via None yesterday
  • No fix available
  • Severity - 5.7 (Medium)
CVE-2026-82049
  • github.com/python/cpython
tarfile extraction filters allow file modification and content disclosure via hard link to symlink 3 days ago
  • Fix available
  • Severity - 8.4 (High)
PSF-0000-CVE-2026-82049
  • github.com/python/cpython
See record for full details 3 days ago
  • Fix available
PSF-2026-41
  • github.com/python/cpython
See record for full details 3 days ago
  • Fix available
CVE-2026-87910
  • github.com/python/cpython
tarfile hardlink fallback ignores custom extraction filter rejection via None 6 days ago
  • Fix available
  • Severity - 5.7 (Medium)
PSF-2026-40
  • github.com/python/cpython
See record for full details 6 days ago
  • Fix available
BIT-python-2026-17084
  • Bitnami/python
stringprep.map_table_b2() deviates from RFC 3454 Table B.2 11 Sep
  • No fix available
  • Severity - 6.0 (Medium)
BIT-python-min-2026-17084
  • Bitnami/python-min
stringprep.map_table_b2() deviates from RFC 3454 Table B.2 11 Sep
  • No fix available
  • Severity - 6.0 (Medium)
BIT-python-2026-15806
  • Bitnami/python
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching 11 Sep
  • No fix available
  • Severity - 6.0 (Medium)
BIT-python-min-2026-15806
  • Bitnami/python-min
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching 11 Sep
  • No fix available
  • Severity - 6.0 (Medium)
BIT-python-2026-15310
  • Bitnami/python
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits 11 Sep
  • No fix available
  • Severity - 2.1 (Low)
BIT-python-min-2026-15310
  • Bitnami/python-min
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits 11 Sep
  • No fix available
  • Severity - 2.1 (Low)
BIT-libpython-2026-17084
  • Bitnami/libpython
stringprep.map_table_b2() deviates from RFC 3454 Table B.2 11 Sep
  • No fix available
  • Severity - 6.0 (Medium)
BIT-libpython-2026-15806
  • Bitnami/libpython
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching 11 Sep
  • No fix available
  • Severity - 6.0 (Medium)