{"schema_version":1,"title":"Python Software Foundation vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 28 vulnerabilities in Python Software Foundation: 0 in the last 7 days and 3 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-6879, was published on 28 July 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/python-software-foundation","json_url":"https://junglewise.ai/threats/vendors/python-software-foundation.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/python-software-foundation","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":5,"all_time":28,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":3,"last_365_days":26},"latest":[{"cve":"CVE-2026-6879","cvss":2,"slug":"cve-2026-6879-python-cpython-quadratic-complexity-in-xml-etree-xpath-index","title":"Python CPython quadratic complexity in xml.etree XPath index predicates","severity":"info","exploited":false,"published_at":"2026-07-28T15:17:51.377+00:00","url":"https://junglewise.ai/threats/cve-2026-6879-python-cpython-quadratic-complexity-in-xml-etree-xpath-index"},{"cve":"CVE-2026-15308","cvss":10,"slug":"cve-2026-15308-python-cpython-cpu-denial-of-service-in-html-parser-htmlparser","title":"Python CPython CPU denial of service in html.parser.HTMLParser","severity":"info","exploited":false,"published_at":"2026-07-09T17:16:58.26+00:00","url":"https://junglewise.ai/threats/cve-2026-15308-python-cpython-cpu-denial-of-service-in-html-parser-htmlparser"},{"cve":"CVE-2026-4360","cvss":2,"slug":"cve-2026-4360-python-cpython-improper-permission-preservation-in-tarfile-extract","title":"Python CPython improper permission preservation in tarfile.extract","severity":"info","exploited":false,"published_at":"2026-06-30T15:16:57.193+00:00","url":"https://junglewise.ai/threats/cve-2026-4360-python-cpython-improper-permission-preservation-in-tarfile-extract"},{"cve":"CVE-2026-11972","cvss":8.2,"slug":"cve-2026-11972-python-cpython-infinite-loop-in-tarfile-streaming-mode","title":"Python CPython infinite loop in tarfile streaming mode","severity":"info","exploited":false,"published_at":"2026-06-23T23:16:49.033+00:00","url":"https://junglewise.ai/threats/cve-2026-11972-python-cpython-infinite-loop-in-tarfile-streaming-mode"},{"cve":"CVE-2026-0864","cvss":4.1,"slug":"cve-2026-0864-python-cpython-configuration-injection-in-configparser","title":"Python CPython configuration injection in configparser","severity":"info","exploited":false,"published_at":"2026-06-23T18:17:41.243+00:00","url":"https://junglewise.ai/threats/cve-2026-0864-python-cpython-configuration-injection-in-configparser"},{"cve":"CVE-2026-11940","cvss":7.8,"slug":"cve-2026-11940-python-cpython-path-traversal-bypass-in-tarfile-extractall","title":"Python CPython path traversal bypass in tarfile.extractall","severity":"info","exploited":false,"published_at":"2026-06-23T17:16:40.847+00:00","url":"https://junglewise.ai/threats/cve-2026-11940-python-cpython-path-traversal-bypass-in-tarfile-extractall"},{"cve":"CVE-2026-12003","cvss":5.3,"slug":"cve-2026-12003-python-uncontrolled-search-path-in-windows-vpath-landmark","title":"Python uncontrolled search path in Windows VPATH landmark detection","severity":"info","exploited":false,"published_at":"2026-06-16T17:16:31.667+00:00","url":"https://junglewise.ai/threats/cve-2026-12003-python-uncontrolled-search-path-in-windows-vpath-landmark"},{"cve":"CVE-2026-9669","cvss":8.2,"slug":"cve-2026-9669-python-cpython-stack-buffer-overflow-in-bz2-bz2decompressor-reuse","title":"Python CPython stack buffer overflow in bz2.BZ2Decompressor reuse","severity":"info","exploited":false,"published_at":"2026-06-08T23:17:25.17+00:00","url":"https://junglewise.ai/threats/cve-2026-9669-python-cpython-stack-buffer-overflow-in-bz2-bz2decompressor-reuse"},{"cve":"CVE-2026-7774","cvss":6.9,"slug":"cve-2026-7774-python-cpython-path-traversal-bypass-in-tarfile-data-filter","title":"Python CPython path traversal bypass in tarfile.data_filter","severity":"info","exploited":false,"published_at":"2026-06-04T16:16:42.103+00:00","url":"https://junglewise.ai/threats/cve-2026-7774-python-cpython-path-traversal-bypass-in-tarfile-data-filter"},{"cve":"CVE-2026-3276","cvss":6.3,"slug":"cve-2026-3276-python-cpython-denial-of-service-in-unicodedata-normalize","title":"Python CPython denial of service in unicodedata.normalize","severity":"info","exploited":false,"published_at":"2026-06-03T16:16:29.253+00:00","url":"https://junglewise.ai/threats/cve-2026-3276-python-cpython-denial-of-service-in-unicodedata-normalize"},{"cve":"CVE-2026-8328","cvss":5.9,"epss":0.0005,"slug":"cve-2026-8328-python-cpython-ssrf-in-ftplib-ftpcp-function","title":"Python CPython SSRF in ftplib.ftpcp function","severity":"info","exploited":false,"published_at":"2026-05-13T21:16:50.167+00:00","url":"https://junglewise.ai/threats/cve-2026-8328-python-cpython-ssrf-in-ftplib-ftpcp-function"},{"cve":"CVE-2026-7210","cvss":9.8,"epss":0.0005,"slug":"cve-2026-7210-python-cpython-denial-of-service-in-xml-parsers","title":"Python CPython denial of service in XML parsers","severity":"critical","exploited":false,"published_at":"2026-05-11T18:16:42.413+00:00","url":"https://junglewise.ai/threats/cve-2026-7210-python-cpython-denial-of-service-in-xml-parsers"},{"cve":"CVE-2026-3087","cvss":7.5,"epss":0.0011,"slug":"cve-2026-3087-python-shutil-path-traversal-in-zip-extraction-on-windows","title":"Python shutil path traversal in ZIP extraction on Windows","severity":"high","exploited":false,"published_at":"2026-04-27T21:16:42.48+00:00","url":"https://junglewise.ai/threats/cve-2026-3087-python-shutil-path-traversal-in-zip-extraction-on-windows"},{"cve":"CVE-2026-6019","cvss":6.1,"epss":0.0006,"slug":"cve-2026-6019-python-cpython-html-injection-in-http-cookies-morsel-js-output","title":"Python CPython HTML injection in http.cookies.Morsel.js_output","severity":"medium","exploited":false,"published_at":"2026-04-22T20:16:42.617+00:00","url":"https://junglewise.ai/threats/cve-2026-6019-python-cpython-html-injection-in-http-cookies-morsel-js-output"},{"cve":"CVE-2026-3298","cvss":8.8,"epss":0.0037,"slug":"cve-2026-3298-python-cpython-out-of-bounds-write-in-asyncio-sock-recvfrom-into","title":"Python CPython out-of-bounds write in asyncio sock_recvfrom_into on Windows","severity":"info","exploited":false,"published_at":"2026-04-21T15:16:37.047+00:00","url":"https://junglewise.ai/threats/cve-2026-3298-python-cpython-out-of-bounds-write-in-asyncio-sock-recvfrom-into"},{"cve":"CVE-2026-5713","cvss":5.3,"epss":0.0002,"slug":"cve-2026-5713-python-cpython-out-of-bounds-read-write-in-remote-debugging","title":"Python CPython out-of-bounds read/write in remote debugging","severity":"info","exploited":false,"published_at":"2026-04-14T16:16:48.717+00:00","url":"https://junglewise.ai/threats/cve-2026-5713-python-cpython-out-of-bounds-read-write-in-remote-debugging"},{"cve":"CVE-2026-4786","cvss":7.1,"epss":0.0021,"slug":"cve-2026-4786-python-cpython-command-injection-bypass-in-webbrowser-module","title":"Python CPython command injection bypass in webbrowser module","severity":"high","exploited":false,"published_at":"2026-04-13T22:16:30.413+00:00","url":"https://junglewise.ai/threats/cve-2026-4786-python-cpython-command-injection-bypass-in-webbrowser-module"},{"cve":"CVE-2026-6100","cvss":8.1,"epss":0.0052,"slug":"cve-2026-6100-python-cpython-use-after-free-in-decompression-modules","title":"Python CPython use-after-free in decompression modules","severity":"high","exploited":false,"published_at":"2026-04-13T18:16:31.297+00:00","url":"https://junglewise.ai/threats/cve-2026-6100-python-cpython-use-after-free-in-decompression-modules"},{"cve":"CVE-2026-1502","cvss":5.7,"epss":0.0002,"slug":"cve-2026-1502-python-cpython-crlf-injection-in-http-client-proxy-tunnel-headers","title":"Python CPython CRLF injection in HTTP client proxy tunnel headers","severity":"info","exploited":false,"published_at":"2026-04-10T18:16:40.97+00:00","url":"https://junglewise.ai/threats/cve-2026-1502-python-cpython-crlf-injection-in-http-client-proxy-tunnel-headers"},{"cve":"CVE-2026-4519","cvss":3.3,"epss":0.0022,"slug":"cve-2026-4519-python-cpython-argument-injection-in-webbrowser-open","title":"Python CPython argument injection in webbrowser.open","severity":"low","exploited":false,"published_at":"2026-03-20T15:16:24.057+00:00","url":"https://junglewise.ai/threats/cve-2026-4519-python-cpython-argument-injection-in-webbrowser-open"},{"cve":"CVE-2026-4224","cvss":7.5,"epss":0.0005,"slug":"cve-2026-4224-python-pyexpat-stack-overflow-in-conv-content-model","title":"Python pyexpat stack overflow in conv_content_model","severity":"high","exploited":false,"published_at":"2026-03-16T18:16:10.07+00:00","url":"https://junglewise.ai/threats/cve-2026-4224-python-pyexpat-stack-overflow-in-conv-content-model"},{"cve":"CVE-2025-13462","cvss":2,"epss":0.0002,"slug":"cve-2025-13462-python-cpython-tarfile-misinterpretation-via-gnu-long-name","title":"Python CPython tarfile misinterpretation via GNU long name normalization","severity":"info","exploited":false,"published_at":"2026-03-12T18:16:21.397+00:00","url":"https://junglewise.ai/threats/cve-2025-13462-python-cpython-tarfile-misinterpretation-via-gnu-long-name"},{"cve":"CVE-2025-15366","cvss":5.9,"epss":0.0032,"slug":"cve-2025-15366-python-cpython-command-injection-in-imaplib","title":"Python CPython command injection in imaplib","severity":"info","exploited":false,"published_at":"2026-01-20T22:15:51.023+00:00","url":"https://junglewise.ai/threats/cve-2025-15366-python-cpython-command-injection-in-imaplib"},{"cve":"CVE-2025-13836","cvss":7.5,"epss":0.0022,"slug":"cve-2025-13836-python-http-client-denial-of-service-via-large-content-length","title":"Python http.client denial of service via large Content-Length header","severity":"high","exploited":false,"published_at":"2025-12-01T18:16:04.2+00:00","url":"https://junglewise.ai/threats/cve-2025-13836-python-http-client-denial-of-service-via-large-content-length"},{"cve":"CVE-2025-6075","cvss":5.5,"epss":0.0014,"slug":"cve-2025-6075-python-cpython-quadratic-complexity-in-os-path-expandvars","title":"Python CPython quadratic complexity in os.path.expandvars","severity":"medium","exploited":false,"published_at":"2025-10-31T17:15:48.693+00:00","url":"https://junglewise.ai/threats/cve-2025-6075-python-cpython-quadratic-complexity-in-os-path-expandvars"}],"vendor":{"hub":true,"name":"Python Software Foundation","slug":"python-software-foundation","homepage":"https://www.python.org/psf-landing/","description":"The Python Software Foundation is a non-profit organization that holds the intellectual property rights for the Python programming language.","url":"https://junglewise.ai/threats/vendors/python-software-foundation"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2016-4000","cvss":9.8,"epss":0.0657,"slug":"cve-2016-4000-jython-insecure-deserialization-in-pyfunction-object","title":"Jython insecure deserialization in PyFunction object","severity":"critical","exploited":false,"published_at":"2022-05-13T01:25:20+00:00","url":"https://junglewise.ai/threats/cve-2016-4000-jython-insecure-deserialization-in-pyfunction-object"},{"cve":"CVE-2026-7210","cvss":9.8,"epss":0.0005,"slug":"cve-2026-7210-python-cpython-denial-of-service-in-xml-parsers","title":"Python CPython denial of service in XML parsers","severity":"critical","exploited":false,"published_at":"2026-05-11T18:16:42.413+00:00","url":"https://junglewise.ai/threats/cve-2026-7210-python-cpython-denial-of-service-in-xml-parsers"},{"cve":"CVE-2026-6100","cvss":8.1,"epss":0.0052,"slug":"cve-2026-6100-python-cpython-use-after-free-in-decompression-modules","title":"Python CPython use-after-free in decompression modules","severity":"high","exploited":false,"published_at":"2026-04-13T18:16:31.297+00:00","url":"https://junglewise.ai/threats/cve-2026-6100-python-cpython-use-after-free-in-decompression-modules"},{"cve":"CVE-2025-13836","cvss":7.5,"epss":0.0022,"slug":"cve-2025-13836-python-http-client-denial-of-service-via-large-content-length","title":"Python http.client denial of service via large Content-Length header","severity":"high","exploited":false,"published_at":"2025-12-01T18:16:04.2+00:00","url":"https://junglewise.ai/threats/cve-2025-13836-python-http-client-denial-of-service-via-large-content-length"},{"cve":"CVE-2026-3087","cvss":7.5,"epss":0.0011,"slug":"cve-2026-3087-python-shutil-path-traversal-in-zip-extraction-on-windows","title":"Python shutil path traversal in ZIP extraction on Windows","severity":"high","exploited":false,"published_at":"2026-04-27T21:16:42.48+00:00","url":"https://junglewise.ai/threats/cve-2026-3087-python-shutil-path-traversal-in-zip-extraction-on-windows"},{"cve":"CVE-2026-4224","cvss":7.5,"epss":0.0005,"slug":"cve-2026-4224-python-pyexpat-stack-overflow-in-conv-content-model","title":"Python pyexpat stack overflow in conv_content_model","severity":"high","exploited":false,"published_at":"2026-03-16T18:16:10.07+00:00","url":"https://junglewise.ai/threats/cve-2026-4224-python-pyexpat-stack-overflow-in-conv-content-model"},{"cve":"CVE-2026-4786","cvss":7.1,"epss":0.0021,"slug":"cve-2026-4786-python-cpython-command-injection-bypass-in-webbrowser-module","title":"Python CPython command injection bypass in webbrowser module","severity":"high","exploited":false,"published_at":"2026-04-13T22:16:30.413+00:00","url":"https://junglewise.ai/threats/cve-2026-4786-python-cpython-command-injection-bypass-in-webbrowser-module"},{"cve":"CVE-2026-6019","cvss":6.1,"epss":0.0006,"slug":"cve-2026-6019-python-cpython-html-injection-in-http-cookies-morsel-js-output","title":"Python CPython HTML injection in http.cookies.Morsel.js_output","severity":"medium","exploited":false,"published_at":"2026-04-22T20:16:42.617+00:00","url":"https://junglewise.ai/threats/cve-2026-6019-python-cpython-html-injection-in-http-cookies-morsel-js-output"},{"cve":"CVE-2025-6075","cvss":5.5,"epss":0.0014,"slug":"cve-2025-6075-python-cpython-quadratic-complexity-in-os-path-expandvars","title":"Python CPython quadratic complexity in os.path.expandvars","severity":"medium","exploited":false,"published_at":"2025-10-31T17:15:48.693+00:00","url":"https://junglewise.ai/threats/cve-2025-6075-python-cpython-quadratic-complexity-in-os-path-expandvars"},{"cve":"CVE-2023-27043","cvss":5.3,"slug":"cve-2023-27043-python-email-module-incorrect-parsing-in-email-utils-parseaddr","title":"Python email module incorrect parsing in email.utils.parseaddr","severity":"medium","exploited":false,"published_at":"2023-04-19T00:15:07.973+00:00","url":"https://junglewise.ai/threats/cve-2023-27043-python-email-module-incorrect-parsing-in-email-utils-parseaddr"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Python Software Foundation CPython","slug":"cpython","vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/cpython"}]}