← All vendors

python

27 known vulnerabilities affecting python products.

Products

python 14 pillow 10 urllib3 2 black 1

Vulnerabilities by priority

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-54058 High 0.5% 9.1 Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncomp…
CVE-2026-21441 Medium 3.0% 7.5 urllib3 is an HTTP client library for Python. urllib3's streaming API is designe…
CVE-2025-13836 Medium 1.6% 7.5 When reading an HTTP response from a server, if no read amount is specified, the…
CVE-2026-4224 Medium 0.7% 7.5 When an Expat parser with a registered ElementDeclHandler parses an inline docum…
CVE-2026-44432 Medium 0.7% 7.5 urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib…
CVE-2026-7210 Medium 0.7% 7.5 `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Exp…
CVE-2026-40192 Medium 0.7% 7.5 Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit…
CVE-2026-15308 Medium 0.6% 7.5 The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-se…
CVE-2026-32274 Medium 0.6% 7.5 Black is the uncompromising Python code formatter. Starting in version 24.3.0 an…
CVE-2026-3087 Medium 0.6% 7.5 If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows pat…
CVE-2026-3644 Medium 0.5% 7.5 The fix for CVE-2026-0672, which rejected control characters in http.cookies.Mor…
CVE-2026-59197 Medium 0.4% 8.2 Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter…
CVE-2026-59204 Medium 0.4% 7.5 Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jp…
CVE-2026-59200 Medium 0.4% 7.5 Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream…
CVE-2026-25990 Medium 0.4% 7.5 Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-boun…
CVE-2026-42311 Medium 0.2% 7.8 Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0…
CVE-2023-6507 Low 1.3% 6.1 An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The…
CVE-2026-4519 Low 0.3% 3.3 The webbrowser.open() API would accept leading dashes in the URL which could be…
CVE-2026-4360 Low 0.3% 5.3 In the Tarfile.extract() function, the filter parameter is not passed properly w…
CVE-2026-6019 Low 0.2% 6.1 http.cookies.Morsel.js_output() returns an inline <script> snippet and only esca…
CVE-2025-13837 Low 0.2% 5.5 When loading a plist file, the plistlib module reads data in size specified by t…
CVE-2025-13462 Low 0.2% 3.3 The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks t…
CVE-2025-6075 Low 0.1% 5.5 If the value passed to os.path.expandvars() is user-controlled a performance de…
CVE-2026-42309 Low 0.1% 5.5 Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0…
CVE-2026-0864 Low 0.1% 5.5 When using the "configparser" module to write configuration files containing mul…
CVE-2026-42310 Low 0.1% 5.5 Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0,…
CVE-2026-42308 Low 0.1% 5.5 Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances …