Search CVE reports


Toggle filters

231 – 240 of 953 results


CVE-2026-24049

Medium priority

Some fixes available 1 of 7

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions...

2 affected packages

wheel, python-pip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wheel Not affected Fixed Not affected Not affected Not affected
python-pip Not affected Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2025-12781

Medium priority
Ignored

When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to...

13 affected packages

pypy3, python3.13, python3.14, python2.7, python3.10...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pypy3 Ignored Ignored Ignored Ignored
python3.13 Not in release Not in release Not in release
python3.14 Ignored Not in release Not in release
python2.7 Not in release Not in release Ignored Ignored Ignored
python3.10 Not in release Not in release Ignored
python3.11 Not in release Not in release Ignored
python3.12 Not in release Ignored Not in release
python3.4 Not in release Not in release Not in release
python3.5 Not in release Not in release Not in release
python3.6 Not in release Not in release Not in release Ignored
python3.7 Not in release Not in release Not in release Ignored
python3.8 Not in release Not in release Not in release Ignored Ignored
python3.9 Not in release Not in release Not in release Ignored
Show all 13 packages Show less packages

CVE-2025-14559

Medium priority
Needs evaluation

A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized use of previously revoked privileges, via a business...

1 affected package

python-keycloak

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-keycloak Not in release Needs evaluation Not in release
Show less packages

CVE-2026-1035

Medium priority
Needs evaluation

A flaw was found in the Keycloak server during refresh token processing, specifically in the TokenManager class responsible for enforcing refresh token reuse policies. When strict refresh token rotation is enabled, the validation...

1 affected package

python-keycloak

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-keycloak Not in release Needs evaluation Not in release
Show less packages

CVE-2026-0865

Medium priority
Fixed

User-controlled header names and values containing newlines can allow injecting HTTP headers.

12 affected packages

python3.13, python2.7, python3.10, python3.11, python3.12...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python3.13 Not in release Not in release Not in release
python2.7 Not in release Not in release Fixed Fixed Fixed
python3.10 Not in release Not in release Fixed
python3.11 Not in release Not in release Fixed
python3.12 Not in release Fixed Not in release
python3.14 Not affected Not in release Not in release
python3.4 Not in release Not in release Not in release
python3.5 Not in release Not in release Not in release
python3.6 Not in release Not in release Not in release Fixed
python3.7 Not in release Not in release Not in release Fixed
python3.8 Not in release Not in release Not in release Fixed Fixed
python3.9 Not in release Not in release Not in release Fixed
Show all 12 packages Show less packages

CVE-2026-0672

Medium priority
Fixed

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.

12 affected packages

python3.13, python2.7, python3.10, python3.11, python3.12...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python3.13 Not in release Not in release Not in release
python2.7 Not in release Not in release Fixed Fixed Fixed
python3.10 Not in release Not in release Fixed
python3.11 Not in release Not in release Fixed
python3.12 Not in release Fixed Not in release
python3.14 Not affected Not in release Not in release
python3.4 Not in release Not in release Not in release
python3.5 Not in release Not in release Not in release
python3.6 Not in release Not in release Not in release Fixed
python3.7 Not in release Not in release Not in release Fixed
python3.8 Not in release Not in release Not in release Fixed Fixed
python3.9 Not in release Not in release Not in release Fixed
Show all 12 packages Show less packages

CVE-2025-15367

Medium priority
Ignored

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

12 affected packages

python3.13, python3.14, python2.7, python3.10, python3.11...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python3.13 Not in release Not in release Not in release
python3.14 Not affected Not in release Not in release
python2.7 Not in release Not in release Ignored Ignored Ignored
python3.10 Not in release Not in release Ignored
python3.11 Not in release Not in release Ignored
python3.12 Not in release Ignored Not in release
python3.4 Not in release Not in release Not in release
python3.5 Not in release Not in release Not in release
python3.6 Not in release Not in release Not in release Ignored
python3.7 Not in release Not in release Not in release Ignored
python3.8 Not in release Not in release Not in release Ignored Ignored
python3.9 Not in release Not in release Not in release Ignored
Show all 12 packages Show less packages

CVE-2025-15366

Medium priority
Ignored

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

12 affected packages

python3.13, python3.14, python2.7, python3.10, python3.11...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python3.13 Not in release Not in release Not in release
python3.14 Not affected Not in release Not in release
python2.7 Not in release Not in release Ignored Ignored Ignored
python3.10 Not in release Not in release Ignored
python3.11 Not in release Not in release Ignored
python3.12 Not in release Ignored Not in release
python3.4 Not in release Not in release Not in release
python3.5 Not in release Not in release Not in release
python3.6 Not in release Not in release Not in release Ignored
python3.7 Not in release Not in release Not in release Ignored
python3.8 Not in release Not in release Not in release Ignored Ignored
python3.9 Not in release Not in release Not in release Ignored
Show all 12 packages Show less packages

CVE-2025-15282

Medium priority
Fixed

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.

12 affected packages

python3.13, python2.7, python3.10, python3.11, python3.12...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python3.13 Not in release Not in release Not in release
python2.7 Not in release Not in release Fixed Fixed Fixed
python3.10 Not in release Not in release Fixed
python3.11 Not in release Not in release Fixed
python3.12 Not in release Fixed Not in release
python3.14 Not affected Not in release Not in release
python3.4 Not in release Not in release Not in release
python3.5 Not in release Not in release Not in release
python3.6 Not in release Not in release Not in release Fixed
python3.7 Not in release Not in release Not in release Fixed
python3.8 Not in release Not in release Not in release Fixed Fixed
python3.9 Not in release Not in release Not in release Fixed
Show all 12 packages Show less packages

CVE-2025-11468

Medium priority
Fixed

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled...

12 affected packages

python3.13, python2.7, python3.10, python3.11, python3.12...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python3.13 Not in release Not in release Not in release
python2.7 Not in release Not in release Not affected Not affected Not affected
python3.10 Not in release Not in release Fixed
python3.11 Not in release Not in release Fixed
python3.12 Not in release Fixed Not in release
python3.14 Not affected Not in release Not in release
python3.4 Not in release Not in release Not in release
python3.5 Not in release Not in release Not in release
python3.6 Not in release Not in release Not in release Fixed
python3.7 Not in release Not in release Not in release Fixed
python3.8 Not in release Not in release Not in release Fixed Fixed
python3.9 Not in release Not in release Not in release Fixed
Show all 12 packages Show less packages