Python
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 399 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 4, 2002 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →[CVE-2026-19672] CPython: tarfile extraction filter bypass allows cation of dictories outside the destination
zipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
tarfile extraction filter bypass allows creation of directories outside the destination
`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching
stringprep.map_table_b2() deviates from RFC 3454 Table B.2
Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
Monitor Python in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.