Search CVE reports
101 – 110 of 952 results
WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using...
1 affected package
python-webob
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python-webob | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with threads/articles into a writer....
3 affected packages
pypdf, pypdf2, python-pypdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pypdf | Needs evaluation | Needs evaluation | Not in release | — | — |
| pypdf2 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| python-pypdf | Not in release | Not in release | Not in release | — | — |
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires merging a file with outlines into a writer. This...
3 affected packages
pypdf, pypdf2, python-pypdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pypdf | Needs evaluation | Needs evaluation | Not in release | — | — |
| pypdf2 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| python-pypdf | Not in release | Not in release | Not in release | — | — |
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires extracting the text in layout mode....
3 affected packages
pypdf, pypdf2, python-pypdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pypdf | Needs evaluation | Needs evaluation | Not in release | — | — |
| pypdf2 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| python-pypdf | Not in release | Not in release | Not in release | — | — |
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting the text of a page which contains a form...
3 affected packages
pypdf, pypdf2, python-pypdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pypdf | Needs evaluation | Needs evaluation | Not in release | — | — |
| pypdf2 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| python-pypdf | Not in release | Not in release | Not in release | — | — |
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter...
3 affected packages
pypdf, pypdf2, python-pypdf
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| pypdf | Needs evaluation | Needs evaluation | Not in release | — | — |
| pypdf2 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
| python-pypdf | Not in release | Not in release | Not in release | — | — |
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses...
1 affected package
python-authlib
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python-authlib | Needs evaluation | Needs evaluation | Needs evaluation | — | — |
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or...
1 affected package
python-aiohttp
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python-aiohttp | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status....
1 affected package
python-aiohttp
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python-aiohttp | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chunk. An attacker may be able to...
1 affected package
python-aiohttp
| Package | 26.04 LTS | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|---|
| python-aiohttp | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |