vendor

python

8 thingsrelated by NVD

Its products

urllib3 4 pillow 2 python 2

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

urllib3: urllib3: Denial of Service due to excessive HTTP response decompression
CVE-2026-44432
Severity high
Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing
CVE-2026-40192
Severity high
pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image
CVE-2026-25990
Severity high
urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
CVE-2026-21441
Severity high
python: Python/Expat: Denial of Service via crafted XML document
CVE-2026-7210
Severity high
urllib3: urllib3 Streaming API improperly handles highly compressed data
CVE-2025-66471
Severity high
urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
CVE-2025-66418
Severity high
python: Quadratic complexity in os.path.expandvars() with user-controlled template
CVE-2025-6075
Severity medium