Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2770▲ 14 respecto a la semana anterior
Críticas / altas1475▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6) | 0.48% | — | Python | 16/3/2026 | 13/8/2026 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to… | |
| Modificada | Alta (8.7) | 0.72% | — | Python Black | 12/3/2026 | 3/8/2026 | Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics option was placed in the filename without sanitization, which allowed an attacker… | |
| Analizada | Baja (2) | 0.16% | — | Python | 12/3/2026 | 13/8/2026 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations. | |
| Analizada | Alta (8.7) | 0.64% | — | Python Black | 11/3/2026 | 17/6/2026 | Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A malicious pull request could edit pyproject.toml to use a direct URL reference to a… | |
| Analizada | Media (6.1) | 0.28% | — | Fedoralovespython Lxml Html Clean | 5/3/2026 | 17/6/2026 | lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the <base> tag passes through the default Cleaner configuration. While page_structure=True removes html, head, and title tags, there is no specific handling for <base>, allowing an attacker to inject… | |
| Analizada | Media (6.1) | 0.29% | — | Fedoralovespython Lxml Html Clean | 5/3/2026 | 17/6/2026 | lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.4, the _has_sneaky_javascript() method strips backslashes before checking for dangerous CSS keywords. This causes CSS Unicode escape sequences to bypass the @import and expression() filters, allowing… | |
| Modificada | Alta (7.5) | 0.59% | — | Python-markdown Markdown | 5/3/2026 | 7/9/2026 | Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This… | |
| Pendiente de análisis | Media (5.7) | 0.20% | — | CpythonAI | 4/3/2026 | 13/8/2026 | The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire. | |
| Modificada | Alta (8.6) | 0.45% | — | Python Pillow | 11/2/2026 | 10/9/2026 | Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1. | |
| Aplazada | Crítica (9.8) | 0.54% | — | Python-diskcache DiskcacheAI | 11/2/2026 | 15/7/2026 | DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache. | |
| Aplazada | Media (5.8) | 0.33% | — | Langsmith Python SDKAIMatrix Javascript SDKAI | 9/2/2026 | 17/6/2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. The LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the baggage header, causing the SDK to exfiltrate sensitive… | |
| Aplazada | Media (5.8) | 0.21% | — | Mcp-run-pythonAI | 9/2/2026 | 17/6/2026 | The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP server - for malicious purposes including MCP tool shadowing. Note - the… | |
| Aplazada | Media (5.8) | 0.20% | — | Pydantic-aiAIPydantic Mcp-run-pythonAIDenoAI | 9/2/2026 | 17/6/2026 | The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the underlying Python code to access the localhost interface of the host to perform SSRF attacks. Note - the "mcp-run-python" project is archived and unlikely to receive a fix. | |
| Analizada | Baja (1.9) | 0.21% | — | Micropython | 6/2/2026 | 17/6/2026 | A flaw has been found in micropython up to 1.27.0. This vulnerability affects the function mp_import_all of the file py/runtime.c. This manipulation causes memory corruption. The attack needs to be launched locally. The exploit has been published and may be used. Patch name: 570744d06c5ba9dba59b4c3f432ca4f0abd396b6.… | |
| Aplazada | Alta (8.2) | 0.26% | — | Amazon Sagemaker Python SDKAINvidia TritonAI | 2/2/2026 | 17/6/2026 | Amazon SageMaker Python SDK before v3.1.1 or v2.256.0 disables TLS certificate verification for HTTPS connections made by the service when a Triton Python model is imported, incorrectly allowing for requests with invalid and self-signed certificates to succeed. | |
| Aplazada | Alta (8.5) | 0.52% | — | Amazon Sagemaker Python SDKAI | 2/2/2026 | 17/6/2026 | The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob function. A third party with permissions to both call this API and permissions to modify objects in the Training Jobs S3 output location may have the… | |
| Modificada | Alta (7.5) | 2.2% | — | Fastapiexpert Python-multipart | 27/1/2026 | 7/8/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious… | |
| Analizada | Media (5) | 0.18% | — | Linuxfoundation Sigstore-python | 26/1/2026 | 17/6/2026 | sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-python OAuth authentication flow is susceptible to Cross-Site Request Forgery. `_OAuthSession` creates a unique "state" and sends it as a parameter in the authentication request but the "state" in… | |
| Aplazada | Media (6) | 0.58% | — | Python Email ModuleAI | 23/1/2026 | 17/6/2026 | The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new… | |
| Analizada | Media (6.3) | 0.57% | — | Python | 21/1/2026 | 17/6/2026 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alternative base64 alphabet" such as the URL safe alphabet. This behavior… | |
| Aplazada | Media (6) | 0.47% | — | Python Http.cookiesAI | 20/1/2026 | 17/6/2026 | When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters. | |
| Aplazada | Media (5.9) | 0.37% | — | Python PoplibAI | 20/1/2026 | 17/6/2026 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. | |
| Aplazada | Media (5.9) | 0.42% | — | Python ImaplibAI | 20/1/2026 | 6/8/2026 | The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. | |
| Aplazada | Media (6) | 0.55% | — | Python UrllibAI | 20/1/2026 | 17/6/2026 | User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype. | |
| Modificada | Alta (8.9) | 3.0% | — | Python Urllib3 | 7/1/2026 | 15/9/2026 | urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding`… |