python security advisories
7 threat alerts tracking vulnerabilities and security advisories that affect python products.
Vulnios monitors python CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent python security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2019-10160 — python, redhat — python, enterprise_linux_desktop
A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which st
criticalCVE-2019-10160Critical Vulnerability: CVE-2019-9636 — python, fedoraproject — python, fedora
Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (cre
criticalCVE-2019-9636Critical Vulnerability: CVE-2019-9948 — python, opensuse — python, leap
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering
criticalCVE-2019-9948Critical Vulnerability: CVE-2025-13462 — python — python
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in
criticalCVE-2025-13462Critical Vulnerability: CVE-2016-5636 — python — python
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negati
criticalCVE-2016-5636Critical Vulnerability: CVE-2016-4009 — python — pillow
Integer overflow in the ImagingResampleHorizontal function in libImaging/Resample.c in Pillow before 3.1.1 allows remote attackers to have unspecified impact via negative values of the new size, which
criticalCVE-2016-4009Critical Vulnerability: CVE-2007-4559 — python — python
Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot)
criticalCVE-2007-4559
Track python exposure across your environment
Vulnios automatically cross-references your asset inventory against new python CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan