Python
38 known vulnerabilities
Top Products
Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bo
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigge
Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component
Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a n
Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-o
Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer w
The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to
Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by
Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from t
Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field f
Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into
Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the P
In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy
When using the "configparser" module to write configuration files containing multi-line text values with carriage return
urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response in
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-le
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could
Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF
Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amo
If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It
Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read
pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current
Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer
When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()
Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi
Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action suppo
Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the
urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HT
Frequently Asked Questions
How many CVEs affect Python?
Python has 38 CVE records in our database, including 2 critical and 21 high severity vulnerabilities.
What are the most severe Python vulnerabilities?
Python has 2 critical severity (CVSS 9.0+) and 21 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Python vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Python products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Python Vulnerabilities
CyberStrike scans your infrastructure for Python vulnerabilities and provides real-time remediation guidance.
Get Started