vendor
python
Severity
Its products
Being told
The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.
Every thing
| urllib3: urllib3: Denial of Service due to excessive HTTP response decompression CVE-2026-44432 | Severity high |
| Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing CVE-2026-40192 | Severity high |
| pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image CVE-2026-25990 | Severity high |
| urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) CVE-2026-21441 | Severity high |
| python: Python/Expat: Denial of Service via crafted XML document CVE-2026-7210 | Severity high |
| urllib3: urllib3 Streaming API improperly handles highly compressed data CVE-2025-66471 | Severity high |
| urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion CVE-2025-66418 | Severity high |
| python: Quadratic complexity in os.path.expandvars() with user-controlled template CVE-2025-6075 | Severity medium |