Search CVE reports


Toggle filters

131 – 140 of 828 results


CVE-2025-68480

Medium priority

Some fixes available 4 of 6

Marshmallow is a lightweight library for converting complex objects to and from simple Python datatypes. In versions from 3.0.0rc1 to before 3.26.2 and from 4.0.0 to before 4.1.2, Schema.load(data, many=True) is vulnerable to...

1 affected package

python-marshmallow

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-marshmallow Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2025-68463

Medium priority
Needs evaluation

Bio.Entrez in Biopython through 186 allows doctype XXE.

1 affected package

python-biopython

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-biopython Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-29370

Medium priority
Needs evaluation

In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token with an exceptionally high compression ratio....

1 affected package

python-jose

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-jose Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-68146

Medium priority

Some fixes available 4 of 7

filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks....

1 affected package

python-filelock

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-filelock Needs evaluation Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-67726

Medium priority
Fixed

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in...

1 affected package

python-tornado

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-tornado Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-67725

Medium priority
Fixed

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add...

1 affected package

python-tornado

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-tornado Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-67724

Medium priority

Some fixes available 5 of 7

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the...

1 affected package

python-tornado

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-tornado Not affected Fixed Fixed Fixed Ignored
Show less packages

CVE-2025-66471

Medium priority

Some fixes available 7 of 18

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of...

2 affected packages

python-urllib3, python-pip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-urllib3 Fixed Fixed Ignored Ignored Ignored
python-pip Fixed Fixed Fixed Ignored Ignored
Show less packages

CVE-2025-66418

Medium priority

Some fixes available 10 of 12

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited...

2 affected packages

python-urllib3, python-pip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-urllib3 Fixed Fixed Fixed Fixed Not affected
python-pip Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2025-6966

Medium priority
Fixed

NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause a denial of service (process crash) via a crafted deb822 file with a malformed non-UTF-8 key.

1 affected package

python-apt

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-apt Fixed Fixed Fixed Fixed
Show less packages