Information on source package python3.13

Available versions

ReleaseVersion
trixie3.13.5-2
forky3.13.12-1
sid3.13.12-1

Open issues

BugtrixieforkysidDescription
CVE-2026-2297vulnerablevulnerablevulnerableThe import hook in CPython that handles legacy *.pyc files (Sourceless ...
CVE-2026-1299vulnerable (no DSA)fixedfixedThe email module, specifically the "BytesGenerator" class, didn\u2019 ...
CVE-2026-0865vulnerable (no DSA)fixedfixedUser-controlled header names and values containing newlines can allow ...
CVE-2026-0672vulnerable (no DSA)fixedfixedWhen using http.cookies.Morsel, user-controlled cookie values and para ...
CVE-2025-15367vulnerable (no DSA)vulnerablevulnerableThe poplib module, when passed a user-controlled command, can have add ...
CVE-2025-15366vulnerable (no DSA)vulnerablevulnerableThe imaplib module, when passed a user-controlled command, can have ad ...
CVE-2025-15282vulnerable (no DSA)fixedfixedUser-controlled data URLs parsed by urllib.request.DataHandler allow i ...
CVE-2025-13837vulnerable (no DSA)fixedfixedWhen loading a plist file, the plistlib module reads data in size spec ...
CVE-2025-13836vulnerable (no DSA)fixedfixedWhen reading an HTTP response from a server, if no read amount is spec ...
CVE-2025-12781vulnerable (no DSA)vulnerablevulnerableWhen passing data to the b64decode(), standard_b64decode(), and urlsaf ...
CVE-2025-12084vulnerable (no DSA)fixedfixedWhen building nested elements using xml.dom.minidom methods such as ap ...
CVE-2025-11468vulnerable (no DSA)fixedfixedWhen folding a long comment in an email header containing exclusively ...
CVE-2025-8291vulnerable (no DSA)fixedfixedThe 'zipfile' module would not check the validity of the ZIP64 End of ...
CVE-2025-8194vulnerable (no DSA)fixedfixedThere is a defect in the CPython \u201ctarfile\u201d module affecting ...
CVE-2025-6075vulnerable (no DSA)fixedfixedIf the value passed to os.path.expandvars() is user-controlled a perf ...
CVE-2025-6069vulnerable (no DSA)fixedfixedThe html.parser.HTMLParser class had worse-case quadratic complexity w ...

Resolved issues

BugDescription
CVE-2025-69534Python-Markdown version 3.8 contain a vulnerability where malformed HT ...
CVE-2025-4517Allows arbitrary filesystem writes outside the extraction directory du ...
CVE-2025-4516There is an issue in CPython when using `bytes.decode("unicode_escape" ...
CVE-2025-4435When using a TarFile.errorlevel = 0and extracting with a filter the do ...
CVE-2025-4330Allows the extraction filter to be ignored, allowing symlink targets t ...
CVE-2025-4138Allows the extraction filter to be ignored, allowing symlink targets t ...
CVE-2025-1795During an address list folding when a separating comma ends up on a fo ...
CVE-2025-0938The Python standard library functions `urllib.parse.urlsplit` and `url ...
CVE-2024-12718Allows modifying some file metadata (e.g. last modified) with filter=" ...
CVE-2024-12254Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writel ...
CVE-2024-9287A vulnerability has been found in the CPython `venv` module and CLI wh ...
CVE-2024-8088There is a HIGH severity vulnerability affecting the CPython "zipfile" ...
CVE-2024-7592There is a LOW severity vulnerability affecting CPython, specifically ...
CVE-2024-6923There is a MEDIUM severity vulnerability affecting CPython. The emai ...
CVE-2024-6232There is a MEDIUM severity vulnerability affecting CPython. Regul ...
CVE-2024-5642CPython 3.9 and earlier doesn't disallow configuring an empty list ("[ ...
CVE-2024-4032The \u201cipaddress\u201d module contained incorrect information about ...
CVE-2024-3220There is a defect in the CPython standard library module \u201cmimetyp ...
CVE-2024-3219The \u201csocket\u201d module provides a pure-Python fallback to the ...
CVE-2024-0397A defect was discovered in the Python \u201cssl\u201d module where the ...

Search for package or bug name: Reporting problems