Known Vulnerabilities for Cpython by Python
Listed below are 1 of the newest known vulnerabilities associated with "Cpython" by "Python".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82049 json | In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives contai... | Not Provided | 2026-09-14 | 2026-10-02 |
| CVE-2026-81878 json | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .py... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-81690 json | openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. ... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-34444 json | Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied... | Not Provided | 2026-04-06 | 2026-07-15 |
| CVE-2026-9769 json | justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTM... | Not Provided | 2026-08-23 | 2026-08-24 |
| CVE-2026-2297 json | The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a bas... | Not Provided | 2026-03-04 | 2026-08-13 |
| CVE-2025-8194 json | There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The ... | Not Provided | 2025-07-28 | 2026-07-31 |
| CVE-2025-4516 json | There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "u... | Not Provided | 2025-05-15 | 2026-07-31 |
| CVE-2024-5642 json | CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an inva... | Not Provided | 2024-06-27 | 2026-07-31 |
| CVE-2023-33595 json | CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobje... | 5.5 - MEDIUM | 2023-06-07 | 2023-06-15 |