Search CVE reports


Toggle filters

241 – 250 of 953 results


CVE-2026-22797

Medium priority
Fixed

An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.12 before 10.12.1. The external_oauth2_token middleware fails to sanitize...

1 affected package

python-keystonemiddleware

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-keystonemiddleware Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-22702

Medium priority
Needs evaluation

virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory...

1 affected package

python-virtualenv

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-virtualenv Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-22701

Medium priority

Some fixes available 4 of 7

filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access...

1 affected package

python-filelock

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-filelock Needs evaluation Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-21860

Medium priority
Not affected

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows device names that have file extensions or trailing spaces. On Windows, there are...

1 affected package

python-werkzeug

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-werkzeug Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-68158

Medium priority

Some fixes available 1 of 3

Authlib is a Python library which builds OAuth and OpenID Connect servers. In version 1.6.5 and prior, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker that...

1 affected package

python-authlib

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-authlib Not affected Fixed Not affected
Show less packages

CVE-2026-21892

Medium priority

Some fixes available 1 of 3

Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. The application constructs SQL queries using unsafe string formatting (Python %...

1 affected package

python-parsl

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-parsl Not affected Fixed Not in release
Show less packages

CVE-2026-21441

Medium priority

Some fixes available 6 of 13

urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at...

2 affected packages

python-pip, python-urllib3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pip Vulnerable Vulnerable Vulnerable Fixed Ignored
python-urllib3 Not affected Fixed Fixed Fixed Ignored
Show less packages

CVE-2025-69230

Medium priority
Ignored

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is accessed in an application,...

1 affected package

python-aiohttp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Ignored Ignored Ignored Ignored
Show less packages

CVE-2025-69229

Medium priority

Some fixes available 5 of 7

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a large number of chunks. If an...

1 affected package

python-aiohttp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Not affected Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-69228

Medium priority

Some fixes available 5 of 7

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontrollably during processing. If an...

1 affected package

python-aiohttp

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-aiohttp Not affected Fixed Fixed Fixed Fixed
Show less packages