LIVE · cybersecurity feed
Live wire
vendor

Python

19 CVEs published in the last four months and 2 stories. Exploited flaws first.

Critical2
High15
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-319009.8criticalblackBlack is the uncompromising Python code formatter.178d ago
CVE-2026-540589.1criticalpillowPillow is a Python imaging library.53d ago
CVE-2026-591978.2highpillowPillow is a Python imaging library.53d ago
CVE-2026-72107.5highpython`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which 117d ago
CVE-2026-444327.5highurllib3urllib3 is an HTTP client library for Python.115d ago
CVE-2026-540597.5highpillowPillow is a Python imaging library.61d ago
CVE-2026-540607.5highpillowPillow is a Python imaging library.61d ago
CVE-2026-553797.5highpillowPillow is a Python imaging library.61d ago
CVE-2026-553807.5highpillowPillow is a Python imaging library.61d ago
CVE-2026-153087.5highpythonThe incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminate58d ago
CVE-2026-591997.5highpillowPillow is a Python imaging library.53d ago
CVE-2026-592047.5highpillowPillow is a Python imaging library.53d ago
CVE-2026-592057.5highpillowPillow is a Python imaging library.53d ago
CVE-2026-592007.5highpillowPillow is a Python imaging library.53d ago
CVE-2026-36447.5highpythonThe fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete.173d ago
CVE-2026-42247.5highpythonWhen an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a de173d ago
CVE-2026-322747.5highblackBlack is the uncompromising Python code formatter.177d ago
CVE-2025-134623.3lowpythonThe "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a177d ago
CVE-2026-45193.3lowpythonThe webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for169d ago

Filter the full tracker by Python

Our coverage of Python

vulnerability

Flaws in Google APK for Python Unlock Agent-to-Agent Attack

Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.

security

HollowFrame Loader Uses Fake Python DLL to Evade Defender

New HollowFrame loader hid Go code in a fake Python DLL after pre-staging Defender exclusions