Common Vulnerabilities and Exposures (CVE)

CVE-2025-4138

Jul 30, 2026 22:15:04 UTC

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract unt...

CVE-2025-4330

Jul 30, 2026 22:14:59 UTC

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract unt...

CVE-2025-4435

Jul 30, 2026 22:14:54 UTC

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that the...

CVE-2025-4516

Jul 30, 2026 22:14:49 UTC

There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop usin...

CVE-2025-4517

Jul 30, 2026 22:14:42 UTC

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or T...

CVE-2025-6069

Jul 30, 2026 22:14:37 UTC

The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.

CVE-2025-6075

Jul 30, 2026 22:14:32 UTC

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVE-2025-8194

Jul 30, 2026 22:14:27 UTC

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlo...

CVE-2025-8291

Jul 30, 2026 22:14:20 UTC

The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous ...

CVE-2026-5846

Jul 30, 2026 22:04:12 UTC

The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interf...

CVE-2026-63362

Jul 30, 2026 22:01:48 UTC

An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.

CVE-2026-65423

Jul 30, 2026 21:59:06 UTC

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.

CVE-2026-63035

Jul 30, 2026 21:56:04 UTC

A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.

CVE-2026-66420

Jul 30, 2026 21:52:28 UTC

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the Chec...

CVE-2026-63559

Jul 30, 2026 21:47:21 UTC

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.