Skip to content
All tracked CVEs

Updated 08:01

241 fixed in the last 7 days

Severity
CVEStatusSeveritySummaryDistributionFixed
FixedHighGitPython 3.1.59 diff API allows --no-index Boolean oracle, arbitrary file disclosuresecure-packages-26.05Sep 18, 2026
FixedHighGitPython <3.1.60 git directory impersonation enables pre-commit hook RCE via tracked filessecure-packages-26.05Sep 18, 2026
FixedHighGitPython <3.1.59 arbitrary file read via Repo.blame() missing --contents/-S denylistsecure-packages-26.05Sep 18, 2026
FixedHighGitPython <3.1.59: separate_git_dir allows arbitrary git directory creation and hook executionsecure-packages-26.05Sep 18, 2026
FixedCriticalGitPython <3.1.59 multi-line config write bug enables directive injection and hook RCEsecure-packages-26.05Sep 18, 2026
FixedHighGitPython before 3.1.59 discloses local files via malicious .gitmodules include directivessecure-packages-26.05Sep 18, 2026
FixedHighPYSEC-2026-2293: ujson.dump memory leak on failed file-like object writes prior to 5.12.1secure-packages-26.05Sep 18, 2026
FixedHighGHSA-c38f-wx89-p2xg: ujson.dump memory leak when write() fails due to missing Py_DECREF of serialized stringsecure-packages-26.05Sep 18, 2026
FixedHighlibcurl LDAP SASL negotiation flaw misinterprets incomplete handshake, enabling MITM peer validation bypasssecure-packages-26.05Sep 18, 2026
FixedMediumPYSEC-2026-3923: sqlparse ReindentFilter CPU DoS when reindent=True processes large crafted tuple-list SQLsecure-packages-26.05Sep 18, 2026
FixedHighPYSEC-2026-3699: sqlparse CPU DoS via O(n*depth) TokenList.__init__ flattening on nested groupssecure-packages-26.05Sep 18, 2026
FixedHighPYSEC-2026-3698: sqlparse ReDoS: dollar-quoted backreference and multiline comments cause quadratic CPU exhaustionsecure-packages-26.05Sep 18, 2026
FixedHighPYSEC-2026-3697: Quadratic parsing of comment-only SQL in sqlparse group_comments enables DoS; token cap bypassedsecure-packages-26.05Sep 18, 2026
FixedMediumPYSEC-2026-3696: sqlparse Python/PHP output modes improperly escape quotes, enabling snippet injection via backslashessecure-packages-26.05Sep 18, 2026
FixedHighPYSEC-2026-3072: Soupsieve CSS parser ReDoS via catastrophic backtracking on unterminated quoted attribute valuessecure-packages-26.05Sep 18, 2026
FixedHighPYSEC-2026-3071: Unbounded memory allocation in soupsieve compiling large comma-separated CSS selector lists (DoS)secure-packages-26.05Sep 18, 2026
FixedHighPYSEC-2026-2292: ujson 5.10–5.11.0 indent overflow/underflow triggers crash or infinite loop DoSsecure-packages-26.05Sep 18, 2026
FixedHighPYSEC-2026-2291: ujson 5.4.0–5.11.0 memory leak parsing large integers enables DoS on untrusted inputsecure-packages-26.05Sep 18, 2026
FixedHighPYSEC-2026-142: urllib3 2.6.x partial reads may fully decompress responses, causing high CPU/memory usesecure-packages-26.05Sep 18, 2026
FixedMediumPYSEC-2026-141: urllib3 ProxyManager cross-origin redirects leak sensitive headers when assert_same_host=False (1.23–<2.7.0)secure-packages-26.05Sep 18, 2026
FixedHighGHSA-wgvc-ghv9-3pmm: ujson 5.4–5.11 accumulating memory leak parsing large integers permits DoSsecure-packages-26.05Sep 18, 2026
FixedHighGHSA-qccp-gfcp-xxvc: urllib3 <2.7.0 ProxyManager-created HTTPConnection cross-origin redirects forward Authorization/Cookie/Proxy-Authorization headerssecure-packages-26.05Sep 18, 2026
FixedHighGHSA-pwgv-4x5q-6m9f: sqlparse parsing DoS: TokenList.__init__ O(n*depth) work on deeply nested SQLsecure-packages-26.05Sep 18, 2026
FixedHighGHSA-prg7-hcfm-mfcr: ReDoS via backreferenced dollar-quote and multiline comment regexes in sqlparse lexersecure-packages-26.05Sep 18, 2026
FixedHighGHSA-mf9v-mfxr-j63j: urllib3 <2.7.0 may fully decompress on Brotli second read or drain_conn, causing resource exhaustionsecure-packages-26.05Sep 18, 2026
FixedHighGHSA-f2ff-p2ww-7p4p: sqlparse group_comments O(n^2) on comment-only input, bypasses token cap, causing DoSsecure-packages-26.05Sep 18, 2026
FixedMediumGHSA-cfqr-cjx5-5jcm: sqlparse ReindentFilter CPU DoS from repeated offset calculations on large tuple listssecure-packages-26.05Sep 18, 2026
FixedHighGHSA-c8rr-9gxc-jprv: ujson.dumps integer overflow/underflow with large or negative indent leads crash/loop DoSsecure-packages-26.05Sep 18, 2026
FixedCriticalUndocumented PLY 3.11 yacc() 'picklefile' enables RCE through unsafe pickle deserializationsecure-packages-rollingSep 18, 2026
FixedHighGHSA-836r-79rf-4m37: soupsieve CSS attribute VALUE regex catastrophic backtracking on unterminated quotes enables ReDoSsecure-packages-26.05Sep 18, 2026
FixedMediumGHSA-3496-9g83-7v6x: sqlparse Python/PHP output formats vulnerable to code injection via improper backslash-quote escapingsecure-packages-26.05Sep 18, 2026
FixedHighGHSA-2wc2-fm75-p42x: Soupsieve/Beautiful Soup CSS parser allocates unbounded memory for large comma-separated selectors causing DoSsecure-packages-26.05Sep 18, 2026
FixedHighlibcurl+libpsl fails PSL enforcement: public-suffix host cookies become wildcard, leak cross-subdomainssecure-packages-26.05Sep 18, 2026
FixedHighlibcurl wolfSSL with CA caching reinstalls cached store after SSL_CTX callback, accepting untrusted certificatessecure-packages-26.05Sep 18, 2026
FixedHighcurl ignores Secure attribute if preceded by tab in Set-Cookie, sending cookie over HTTPsecure-packages-26.05Sep 18, 2026
FixedHighlibcurl erroneously reuses HTTPS connections across different CURLSSLOPT_NATIVE_CA settings for same hostsecure-packages-26.05Sep 18, 2026
FixedHighlibcurl ignores CURLOPT_PINNEDPUBLICKEY when verification disabled and server presents no certificatesecure-packages-26.05Sep 18, 2026
FixedHighlibcurl multi/OpenSSL 3: pooled TLS outlives easy handle, dangling libctx leads to UAFsecure-packages-26.05Sep 18, 2026
FixedMediumgst-plugins-good avidemux vprp parsing OOB read causes crash via crafted AVIsecure-packages-26.05Sep 18, 2026
FixedHighSoupsieve <2.8.4 regex catastrophic backtracking via unterminated attribute selector causes DoSsecure-packages-26.05Sep 18, 2026
FixedHighsoupsieve pre-2.8.4 CSS selector parser unbounded memory allocation DoS via crafted selectorssecure-packages-26.05Sep 18, 2026
FixedMediumMP4 parsing DoS: GStreamer isomp4 qtdemux_audio_caps divide-by-zero from unvalidated atoms (<1.28.2)secure-packages-26.05Sep 18, 2026
FixedMediumGStreamer gst-plugins-good <1.28.2 isomp4 qtdemux_parse_trak divide-by-zero DoS on MP4 audiosecure-packages-26.05Sep 18, 2026
FixedCriticallibcurl reuses Negotiate-auth HTTP connection after empty creds, leaking requests across userssecure-packages-26.05Sep 18, 2026
FixedCriticalUse-after-free in libcurl cleanup when sharing connections during HTTP/2 Server Pushsecure-packages-26.05Sep 18, 2026
FixedHighUse-after-free RCE in GStreamer rtpsbcdepay RTP payload handling (ZDI-CAN-29787)secure-packages-26.05Sep 18, 2026
FixedHighGStreamer PNG parser heap overflow allows RCE via malicious PNG; user interaction requiredsecure-packages-26.05Sep 18, 2026
FixedHighGStreamer OGG parser stack-based buffer overflow allows remote code execution; user interaction requiredsecure-packages-26.05Sep 18, 2026
FixedHighGStreamer MRF parsing heap buffer overflow enables RCE via crafted file (ZDI-CAN-29608)secure-packages-26.05Sep 18, 2026
FixedHighGStreamer MRF parser out-of-bounds write enables remote code execution (ZDI-CAN-29510)secure-packages-26.05Sep 18, 2026

Contact sales

Provide us with some basic details and we'll follow up with you about , usually within one business day.

We'll only use this to get back to you. See our privacy policy (opens in a new tab). This site is protected by reCAPTCHA and the Google Privacy Policy (opens in a new tab) and Terms of Service (opens in a new tab) apply.