Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations
Configuration Injection via Carriage Return (\r) in write() method
xml.parsers.expat and xml.etree.ElementTree use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.
If shutil.unpackarchive() is given a ZIP archive with an absolute Windows path containing a drive (C:\\...) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this vulnerability.
BaseCookie.jsoutput() does not neutralize embedded characters
Last updated 6 July 2026
Last updated 10 September 2026
Incomplete control character validation in http.cookies
tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling