Vulnerabilities

Summary — last 7 days

New vulnerabilities3,302▲ 384 vs. last week
Critical / high1,464▲ 142 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)591▲ 117 vs. last week
–

647 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisHigh (8.1)0.72%—Ansible Community.generalAIMemcachedAIPython-memcachedAI9/9/20269/9/2026
A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached…
AnalyzedHigh (8.7)0.52%—Gitpython Project Gitpython9/9/20269/18/2026
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause quadratic backtracking, exhausting CPU…
AnalyzedHigh (7.1)0.41%—Gitpython Project Gitpython9/9/20269/16/2026
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create a content-dependent Boolean oracle, repeatedly querying local files to recover…
AnalyzedHigh (8.7)0.40%—Gitpython Project Gitpython9/9/20269/16/2026
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a malicious pre-commit hook in the tracked hooks directory that executes when a victim…
Awaiting AnalysisCritical (10)0.74%—Google Cloud Agent Development KITAIPythonAI9/9/20269/9/2026
A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.
Awaiting AnalysisHigh (8.5)0.44%—PythonAIXmlsoft Libxml2AI9/8/20269/28/2026
A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a…
Awaiting AnalysisMedium (6.5)0.12%—Snowflake Python DriverAISnowflake GO DriverAISnowflake Jdbc DriverAISnowflake Node.js DriverAI+29/8/20269/10/2026
Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction did…
Awaiting AnalysisHigh (7.4)0.16%—Snowflake Python DriverAISnowflake GO DriverAISnowflake Jdbc DriverAISnowflake Node.js DriverAI9/4/20269/10/2026
Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle…
DeferredCritical (9.3)0.35%—Python-joseAI9/3/20269/24/2026
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an…
Awaiting AnalysisHigh (8.5)0.63%—Amazon Sagemaker Python SDKAI9/1/20269/3/2026
Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for…
DeferredCritical (9.3)0.85%—TouluniverseAIPythonAI8/27/20269/23/2026
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source for a denied list of attribute names and calls but left the attribute-lookup…
Awaiting AnalysisLow (2.1)0.51%—PythonAI8/25/202610/1/2026
When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controlled size to pre-allocate memory, possibly resulting in memory exhaustion.
Awaiting AnalysisHigh (7.1)0.26%—GitpythonAI8/25/20269/24/2026
GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arbitrary files, with contents returned in the annotated tag message.
AnalyzedHigh (7.1)0.41%—Gitpython Project Gitpython8/25/20269/2/2026
GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by passing these options to Repo.blame(). Attackers can supply revision values like --contents=/etc/passwd to leak file contents…
AnalyzedHigh (8.7)0.65%—Gitpython Project Gitpython8/25/20269/2/2026
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled…
AnalyzedCritical (9.3)0.78%—Gitpython Project Gitpython8/25/20269/2/2026
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write,…
AnalyzedHigh (8.6)0.18%—Gitpython Project Gitpython8/25/20269/2/2026
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is…
DeferredHigh (8.5)1.3%—Agno PythontoolsAI8/19/20269/24/2026
Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to read_file, save_to_file, or run_python_file tool actions. Attackers can…
Awaiting AnalysisMedium (6.3)0.52%—Python TarfileAI8/19/20268/28/2026
The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given. Only empty…
AnalyzedHigh (8.4)0.42%—Gitpython Project Gitpython8/19/20269/2/2026
GitPython before 3.1.58 fails to validate submodule names from .gitmodules files, allowing attackers to create Git repositories at arbitrary filesystem paths outside the intended clone directory. Attackers can craft malicious repositories with traversal sequences in submodule names that GitPython processes during…
AnalyzedHigh (8.7)0.77%—Gitpython Project Gitpython8/19/20269/2/2026
GitPython before 3.1.58 contains a config-name injection vulnerability in the option-name validator that allows attackers to forge arbitrary git-config directives by injecting equals signs, hash symbols, and whitespace into option names. Attackers can inject malicious option names like 'sshCommand = touch /tmp/RCE #'…
AnalyzedHigh (8.7)0.91%—Gitpython Project Gitpython8/19/20269/3/2026
GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted kwargs dictionary to guarded methods like clone_from to emit a joined token parsed as…
AnalyzedHigh (7.2)0.54%—Gitpython Project Gitpython8/19/20269/3/2026
GitPython versions before 3.1.58 contain an arbitrary file overwrite vulnerability in IndexFile.from_tree, IndexFile.reset, and IndexFile.merge_tree methods that append caller-influenced treeish strings to git read-tree without option validation or argument separation. Attackers can inject the --index-output option to…
AnalyzedHigh (7.7)0.83%—Gitpython Project Gitpython8/19/20269/3/2026
GitPython before 3.1.58 contains a remote code execution vulnerability in Repo.init that forwards unsafe git options without validation. Attackers can supply a template parameter pointing to a directory with malicious git hooks that execute arbitrary code when git operations are performed on the initialized repository.
AnalyzedHigh (7.1)0.41%—Gitpython Project Gitpython8/19/20269/3/2026
GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attackers can supply --pathspec-from-file and --pathspec-file-nul parameters to read arbitrary files accessible to the process, with full file contents returned in…