Information on source package python3.14

Available versions

ReleaseVersion
forky3.14.3-3
sid3.14.4-1

Open issues

BugforkysidDescription
CVE-2026-6100vulnerablevulnerableUse-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2 ...
CVE-2026-5713vulnerablevulnerableThe "profiling.sampling" module (Python 3.15+) and "asyncio introspect ...
CVE-2026-4786vulnerablevulnerableMitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ...
CVE-2026-4519vulnerablefixedThe webbrowser.open() API would accept leading dashes in the URL which ...
CVE-2026-4224vulnerablefixedWhen an Expat parser with a registered ElementDeclHandler parses an in ...
CVE-2026-3644vulnerablefixedThe fix for CVE-2026-0672, which rejected control characters in http.c ...
CVE-2026-3446vulnerablefixedWhen calling base64.b64decode() or related functions the decoding proc ...
CVE-2026-2297vulnerablefixedThe import hook in CPython that handles legacy *.pyc files (Sourceless ...
CVE-2026-1502vulnerablevulnerableCR/LF bytes were not rejected by HTTP client proxy tunnel headers or h ...
CVE-2025-15367vulnerablevulnerableThe poplib module, when passed a user-controlled command, can have add ...
CVE-2025-15366vulnerablevulnerableThe imaplib module, when passed a user-controlled command, can have ad ...
CVE-2025-13462vulnerablefixedThe "tarfile" module would still apply normalization of AREGTYPE (\x00 ...
CVE-2025-12781vulnerablevulnerableWhen passing data to the b64decode(), standard_b64decode(), and urlsaf ...

Open unimportant issues

BugforkysidDescription
CVE-2026-3479vulnerablevulnerableDISPUTED: The project has clarified that the documentation was incorre ...

Resolved issues

BugDescription
CVE-2026-1299The email module, specifically the "BytesGenerator" class, didn\u2019 ...
CVE-2026-0865User-controlled header names and values containing newlines can allow ...
CVE-2026-0672When using http.cookies.Morsel, user-controlled cookie values and para ...
CVE-2025-69534Python-Markdown version 3.8 contain a vulnerability where malformed HT ...
CVE-2025-15282User-controlled data URLs parsed by urllib.request.DataHandler allow i ...
CVE-2025-13837When loading a plist file, the plistlib module reads data in size spec ...
CVE-2025-13836When reading an HTTP response from a server, if no read amount is spec ...
CVE-2025-12084When building nested elements using xml.dom.minidom methods such as ap ...
CVE-2025-11468When folding a long comment in an email header containing exclusively ...
CVE-2025-8291The 'zipfile' module would not check the validity of the ZIP64 End of ...
CVE-2025-6075If the value passed to os.path.expandvars() is user-controlled a perf ...

Search for package or bug name: Reporting problems