Vendor
Python Software Foundation vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 28 vulnerabilities in Python Software Foundation: 0 in the last 7 days and 3 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-6879, was published on 28 July 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 3
- Critical, all time
- 2
- Exploited in the wild
- 0
About Python Software Foundation
The Python Software Foundation is a non-profit organization that holds the intellectual property rights for the Python programming language.
Python Software Foundation technologies
Latest Python Software Foundation vulnerabilities
- CVE-2026-6879: Python CPython quadratic complexity in xml.etree XPath index predicatesinfoCVSS 2
- CVE-2026-15308: Python CPython CPU denial of service in html.parser.HTMLParserinfoCVSS 10
- CVE-2026-4360: Python CPython improper permission preservation in tarfile.extractinfoCVSS 2
- CVE-2026-11972: Python CPython infinite loop in tarfile streaming modeinfoCVSS 8.2
- CVE-2026-0864: Python CPython configuration injection in configparserinfoCVSS 4.1
- CVE-2026-11940: Python CPython path traversal bypass in tarfile.extractallinfoCVSS 7.8
- CVE-2026-12003: Python uncontrolled search path in Windows VPATH landmark detectioninfoCVSS 5.3
- CVE-2026-9669: Python CPython stack buffer overflow in bz2.BZ2Decompressor reuseinfoCVSS 8.2
- CVE-2026-7774: Python CPython path traversal bypass in tarfile.data_filterinfoCVSS 6.9
- CVE-2026-3276: Python CPython denial of service in unicodedata.normalizeinfoCVSS 6.3
- CVE-2026-8328: Python CPython SSRF in ftplib.ftpcp functioninfoCVSS 5.9EPSS 0.1%
- CVE-2026-7210: Python CPython denial of service in XML parserscriticalCVSS 9.8EPSS 0.1%
- CVE-2026-3087: Python shutil path traversal in ZIP extraction on WindowshighCVSS 7.5EPSS 0.1%
- CVE-2026-6019: Python CPython HTML injection in http.cookies.Morsel.js_outputmediumCVSS 6.1EPSS 0.1%
- CVE-2026-3298: Python CPython out-of-bounds write in asyncio sock_recvfrom_into on WindowsinfoCVSS 8.8EPSS 0.4%
- CVE-2026-5713: Python CPython out-of-bounds read/write in remote debugginginfoCVSS 5.3EPSS 0.0%
- CVE-2026-4786: Python CPython command injection bypass in webbrowser modulehighCVSS 7.1EPSS 0.2%
- CVE-2026-6100: Python CPython use-after-free in decompression moduleshighCVSS 8.1EPSS 0.5%
- CVE-2026-1502: Python CPython CRLF injection in HTTP client proxy tunnel headersinfoCVSS 5.7EPSS 0.0%
- CVE-2026-4519: Python CPython argument injection in webbrowser.openlowCVSS 3.3EPSS 0.2%
- CVE-2026-4224: Python pyexpat stack overflow in conv_content_modelhighCVSS 7.5EPSS 0.1%
- CVE-2025-13462: Python CPython tarfile misinterpretation via GNU long name normalizationinfoCVSS 2EPSS 0.0%
- CVE-2025-15366: Python CPython command injection in imaplibinfoCVSS 5.9EPSS 0.3%
- CVE-2025-13836: Python http.client denial of service via large Content-Length headerhighCVSS 7.5EPSS 0.2%
- CVE-2025-6075: Python CPython quadratic complexity in os.path.expandvarsmediumCVSS 5.5EPSS 0.1%
Most severe Python Software Foundation vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2016-4000: Jython insecure deserialization in PyFunction objectcriticalCVSS 9.8EPSS 6.6%
- CVE-2026-7210: Python CPython denial of service in XML parserscriticalCVSS 9.8EPSS 0.1%
- CVE-2026-6100: Python CPython use-after-free in decompression moduleshighCVSS 8.1EPSS 0.5%
- CVE-2025-13836: Python http.client denial of service via large Content-Length headerhighCVSS 7.5EPSS 0.2%
- CVE-2026-3087: Python shutil path traversal in ZIP extraction on WindowshighCVSS 7.5EPSS 0.1%
- CVE-2026-4224: Python pyexpat stack overflow in conv_content_modelhighCVSS 7.5EPSS 0.1%
- CVE-2026-4786: Python CPython command injection bypass in webbrowser modulehighCVSS 7.1EPSS 0.2%
- CVE-2026-6019: Python CPython HTML injection in http.cookies.Morsel.js_outputmediumCVSS 6.1EPSS 0.1%
- CVE-2025-6075: Python CPython quadratic complexity in os.path.expandvarsmediumCVSS 5.5EPSS 0.1%
- CVE-2023-27043: Python email module incorrect parsing in email.utils.parseaddrmediumCVSS 5.3
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/python-software-foundation.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Python Software Foundation vulnerabilities", https://junglewise.ai/threats/vendors/python-software-foundation, 26 September 2026.