0
I Use This!
Very Low Activity
Analyzed 1 day ago. based on code collected 2 days ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2026-7210 High May 11, 2026 `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to tri more...
3.11.17, 3.10.22, 3.12.15, 3.11.16, 3.10.21, 3.12.14, 3.14.5, 3.13.13, 3.14.4, 3.12.13
CVE-2026-6019 BDSA-2026-8103 Medium Apr 22, 2026 http.cookies.Morsel.js_output() returns an inline snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sen more...
3.11.17, 3.10.22, 3.12.15, 3.11.16, 3.10.21, 3.12.14, 3.14.5, 3.13.13, 3.14.4, 3.12.13
CVE-2026-4519 Low Mar 20, 2026 The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavio more...
3.11.17, 3.10.22, 3.12.15, 3.11.16, 3.10.21, 3.12.14, 3.12.13, 3.11.15, 3.10.20, 3.13.12
CVE-2026-3644 High Mar 16, 2026 The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling p more...
3.11.17, 3.10.22, 3.12.15, 3.11.16, 3.10.21, 3.12.14, 3.12.13, 3.11.15, 3.10.20, 3.13.12
CVE-2026-3087 High Apr 27, 2026 If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted out more...
3.11.17, 3.10.22, 3.12.15, 3.13.16, 3.11.16, 3.10.21, 3.12.14, 3.13.15, 3.13.14, 3.13.13
CVE-2025-13837 Medium Dec 01, 2025 When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
3.11.17, 3.10.22, 3.12.15, 3.11.16, 3.10.21, 3.12.14, 3.12.13, 3.11.15, 3.10.20, 3.9.25
CVE-2025-13462 Low Mar 12, 2026 The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_L more...
3.11.17, 3.10.22, 3.12.15, 3.11.16, 3.10.21, 3.12.14, 3.12.13, 3.11.15, 3.10.20, 3.13.12
CVE-2025-12781 Medium Jan 21, 2026 When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be more...
3.11.17, 3.10.22, 3.12.15, 3.11.16, 3.10.21, 3.12.14, 3.12.13, 3.11.15, 3.10.20, 3.9.25
CVE-2025-12084 Medium Dec 03, 2025 When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadrati more...
3.11.17, 3.10.22, 3.12.15, 3.11.16, 3.10.21, 3.12.14, 3.12.13, 3.11.15, 3.10.20, 3.14.1
BDSA-2026-6872 Medium Apr 13, 2026 CPython is vulnerable to data integrity issues due to improper handling of excess padding in the `base64.b64decode` function. A remote attacker could e more...