| Twisted |
CVE-2026-42304 |
高危 |
22.8.0 |
26.4.0rc2 |
python-twisted: Twisted: Denial of Service via crafted DNS packets in twisted.names
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-42304
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-05-13 21:16 修改: 2026-06-17 10:47
|
| certifi |
CVE-2023-37920 |
高危 |
2022.9.24 |
2023.7.22 |
python-certifi: Removal of e-Tugra root certificate
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-37920
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2023-07-25 21:15 修改: 2026-06-17 06:08
|
| cryptography |
CVE-2023-0286 |
高危 |
38.0.1 |
39.0.1 |
openssl: X.400 address type confusion in X.509 GeneralName
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-0286
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2023-02-08 20:15 修改: 2026-06-17 05:25
|
| cryptography |
CVE-2023-50782 |
高危 |
38.0.1 |
42.0.0 |
python-cryptography: Bleichenbacher timing oracle attack against RSA decryption - incomplete fix for CVE-2020-25659
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-50782
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2024-02-05 21:15 修改: 2026-06-17 06:39
|
| cryptography |
CVE-2024-26130 |
高危 |
38.0.1 |
42.0.4 |
python-cryptography: NULL pointer dereference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash override
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26130
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2024-02-21 17:15 修改: 2026-06-17 07:17
|
| cryptography |
CVE-2026-26007 |
高危 |
38.0.1 |
46.0.5 |
cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-26007
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-02-10 22:17 修改: 2026-07-20 12:18
|
| cryptography |
CVE-2026-69249 |
高危 |
38.0.1 |
49.0.0 |
python-cryptography is a package designed to expose cryptographic prim ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-69249
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-08-03 22:16 修改: 2026-08-04 15:16
|
| cryptography |
GHSA-537c-gmf6-5ccf |
高危 |
38.0.1 |
48.0.1 |
Vulnerable OpenSSL included in cryptography wheels
漏洞详情: https://github.com/advisories/GHSA-537c-gmf6-5ccf
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-06-15 20:12 修改: 2026-06-15 20:12
|
| pyasn1 |
CVE-2026-30922 |
高危 |
0.4.8 |
0.6.3 |
pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-30922
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-03-18 04:17 修改: 2026-08-05 13:21
|
| pyasn1 |
CVE-2026-59884 |
高危 |
0.4.8 |
0.6.4 |
python-pyasn1: pyasn1: Denial of Service via crafted BER input
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59884
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-07-14 17:17 修改: 2026-07-21 14:37
|
| pyasn1 |
CVE-2026-59885 |
高危 |
0.4.8 |
0.6.4 |
pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59885
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-07-14 17:17 修改: 2026-07-21 14:38
|
| pyasn1 |
CVE-2026-59886 |
高危 |
0.4.8 |
0.6.4 |
pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59886
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-07-14 17:17 修改: 2026-07-21 14:38
|
| setuptools |
CVE-2022-40897 |
高危 |
57.5.0 |
65.5.1 |
pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-40897
镜像层: sha256:ddf2ea8997bb4bb9b003e9f5b21215786a971359b97f9ce6e9902ec575a5e21d
发布日期: 2022-12-23 00:15 修改: 2026-06-17 05:02
|
| setuptools |
CVE-2024-6345 |
高危 |
57.5.0 |
70.0.0 |
pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-6345
镜像层: sha256:ddf2ea8997bb4bb9b003e9f5b21215786a971359b97f9ce6e9902ec575a5e21d
发布日期: 2024-07-15 01:15 修改: 2026-06-17 08:17
|
| setuptools |
CVE-2025-47273 |
高危 |
57.5.0 |
78.1.1 |
setuptools: Path Traversal Vulnerability in setuptools PackageIndex
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-47273
镜像层: sha256:ddf2ea8997bb4bb9b003e9f5b21215786a971359b97f9ce6e9902ec575a5e21d
发布日期: 2025-05-17 16:15 修改: 2026-06-17 09:27
|
| urllib3 |
CVE-2023-43804 |
高危 |
1.26.12 |
2.0.6, 1.26.17 |
python-urllib3: Cookie request header isn't stripped during cross-origin redirects
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-43804
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2023-10-04 17:15 修改: 2026-06-17 06:26
|
| urllib3 |
CVE-2025-66418 |
高危 |
1.26.12 |
2.6.0 |
urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66418
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2025-12-05 16:15 修改: 2026-06-17 09:56
|
| urllib3 |
CVE-2025-66471 |
高危 |
1.26.12 |
2.6.0 |
urllib3: urllib3 Streaming API improperly handles highly compressed data
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-66471
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2025-12-05 17:16 修改: 2026-06-17 09:56
|
| urllib3 |
CVE-2026-21441 |
高危 |
1.26.12 |
2.6.3 |
urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-21441
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-01-07 22:15 修改: 2026-08-10 13:17
|
| urllib3 |
CVE-2026-44431 |
高危 |
1.26.12 |
2.7.0 |
urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-44431
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-05-13 16:16 修改: 2026-06-26 12:16
|
| wheel |
CVE-2022-40898 |
高危 |
0.37.1 |
0.38.1 |
python-wheel: remote attackers can cause denial of service via attacker controlled input to wheel cli
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-40898
镜像层: sha256:ddf2ea8997bb4bb9b003e9f5b21215786a971359b97f9ce6e9902ec575a5e21d
发布日期: 2022-12-23 00:15 修改: 2026-06-17 05:02
|
| pip |
CVE-2023-5752 |
中危 |
22.0.4 |
23.3 |
pip: Mercurial configuration injectable in repo revision when installing via pip
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-5752
镜像层: sha256:ddf2ea8997bb4bb9b003e9f5b21215786a971359b97f9ce6e9902ec575a5e21d
发布日期: 2023-10-25 18:17 修改: 2026-06-17 06:49
|
| pip |
CVE-2025-8869 |
中危 |
22.0.4 |
25.3 |
pip: pip missing checks on symbolic link extraction
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-8869
镜像层: sha256:ddf2ea8997bb4bb9b003e9f5b21215786a971359b97f9ce6e9902ec575a5e21d
发布日期: 2025-09-24 15:15 修改: 2026-06-17 10:07
|
| pip |
CVE-2026-3219 |
中危 |
22.0.4 |
26.1 |
pip: pip: Incorrect file installation due to improper archive handling
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-3219
镜像层: sha256:ddf2ea8997bb4bb9b003e9f5b21215786a971359b97f9ce6e9902ec575a5e21d
发布日期: 2026-04-20 16:16 修改: 2026-06-17 10:43
|
| pip |
CVE-2026-6357 |
中危 |
22.0.4 |
26.1 |
pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-6357
镜像层: sha256:ddf2ea8997bb4bb9b003e9f5b21215786a971359b97f9ce6e9902ec575a5e21d
发布日期: 2026-04-27 15:16 修改: 2026-06-17 11:00
|
| pip |
CVE-2026-8643 |
中危 |
22.0.4 |
26.1.2 |
python-pip: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-8643
镜像层: sha256:ddf2ea8997bb4bb9b003e9f5b21215786a971359b97f9ce6e9902ec575a5e21d
发布日期: 2026-06-01 17:17 修改: 2026-08-05 13:24
|
| Twisted |
CVE-2024-41671 |
中危 |
22.8.0 |
24.7.0rc1 |
Twisted is an event-based framework for internet applications, support ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-41671
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2024-07-29 15:15 修改: 2026-06-17 07:48
|
| Twisted |
CVE-2024-41810 |
中危 |
22.8.0 |
24.7.0rc1 |
python-twisted: Reflected XSS via HTML Injection in Redirect Response
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-41810
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2024-07-29 16:15 修改: 2026-06-17 07:48
|
| Twisted |
CVE-2022-39348 |
中危 |
22.8.0 |
22.10.0rc1 |
python-twisted: NameVirtualHost Host header injection
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-39348
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2022-10-26 20:15 修改: 2026-06-17 04:58
|
| certifi |
CVE-2022-23491 |
中危 |
2022.9.24 |
2022.12.07 |
python-certifi: untrusted root certificates
漏洞详情: https://avd.aquasec.com/nvd/cve-2022-23491
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2022-12-07 22:15 修改: 2026-06-17 04:30
|
| requests |
CVE-2023-32681 |
中危 |
2.28.1 |
2.31.0 |
python-requests: Unintended leak of Proxy-Authorization header
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-32681
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2023-05-26 18:15 修改: 2026-06-17 05:59
|
| requests |
CVE-2024-35195 |
中危 |
2.28.1 |
2.32.0 |
requests: subsequent requests to the same host ignore cert verification
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-35195
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2024-05-20 21:15 修改: 2026-06-17 07:34
|
| requests |
CVE-2024-47081 |
中危 |
2.28.1 |
2.32.4 |
requests: Requests vulnerable to .netrc credentials leak via malicious URLs
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47081
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2025-06-09 18:15 修改: 2026-06-17 07:56
|
| requests |
CVE-2026-25645 |
中危 |
2.28.1 |
2.33.0 |
requests: Requests: Security bypass due to predictable temporary file creation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-25645
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-03-25 17:16 修改: 2026-06-17 10:25
|
| Twisted |
CVE-2023-46137 |
中危 |
22.8.0 |
23.10.0rc1 |
python-twisted: disordered HTTP pipeline response in twisted.web
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-46137
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2023-10-25 21:15 修改: 2026-06-17 06:30
|
| cryptography |
CVE-2023-23931 |
中危 |
38.0.1 |
39.0.1 |
python-cryptography: memory corruption via immutable objects
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-23931
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2023-02-07 21:15 修改: 2026-06-17 05:38
|
| cryptography |
CVE-2023-49083 |
中危 |
38.0.1 |
41.0.6 |
python-cryptography: NULL-dereference when loading PKCS7 certificates
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-49083
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2023-11-29 19:15 修改: 2026-06-17 06:35
|
| setuptools |
CVE-2026-59890 |
中危 |
57.5.0 |
83.0.0 |
setuptools: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD)
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-59890
镜像层: sha256:ddf2ea8997bb4bb9b003e9f5b21215786a971359b97f9ce6e9902ec575a5e21d
发布日期: 2026-07-08 17:17 修改: 2026-07-13 17:04
|
| cryptography |
CVE-2024-0727 |
中危 |
38.0.1 |
42.0.2 |
openssl: denial of service via null dereference
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-0727
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2024-01-26 09:15 修改: 2026-06-17 06:54
|
| cryptography |
CVE-2026-69248 |
中危 |
38.0.1 |
49.0.0 |
cryptography is a package designed to expose cryptographic primitives ...
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-69248
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-08-03 22:16 修改: 2026-08-04 16:16
|
| cryptography |
GHSA-39hc-v87j-747x |
中危 |
38.0.1 |
38.0.3 |
Vulnerable OpenSSL included in cryptography wheels
漏洞详情: https://github.com/advisories/GHSA-39hc-v87j-747x
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2022-11-02 18:11 修改: 2022-11-02 18:11
|
| cryptography |
GHSA-h4gh-qq45-vh27 |
中危 |
38.0.1 |
43.0.1 |
pyca/cryptography has a vulnerable OpenSSL included in cryptography wheels
漏洞详情: https://github.com/advisories/GHSA-h4gh-qq45-vh27
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2024-09-03 21:59 修改: 2024-09-03 21:59
|
| idna |
CVE-2024-3651 |
中危 |
3.4 |
3.7 |
python-idna: potential DoS via resource consumption via specially crafted inputs to idna.encode()
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-3651
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2024-07-07 18:15 修改: 2026-06-17 07:44
|
| urllib3 |
CVE-2023-45803 |
中危 |
1.26.12 |
2.0.7, 1.26.18 |
urllib3: Request body not stripped after redirect from 303 status changes request method to GET
漏洞详情: https://avd.aquasec.com/nvd/cve-2023-45803
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2023-10-17 20:15 修改: 2026-06-17 06:29
|
| urllib3 |
CVE-2024-37891 |
中危 |
1.26.12 |
1.26.19, 2.2.2 |
urllib3: proxy-authorization request header is not stripped during cross-origin redirects
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-37891
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2024-06-17 20:15 修改: 2026-06-17 07:38
|
| urllib3 |
CVE-2025-50181 |
中危 |
1.26.12 |
2.5.0 |
urllib3: urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
漏洞详情: https://avd.aquasec.com/nvd/cve-2025-50181
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2025-06-19 01:15 修改: 2026-06-17 09:34
|
| idna |
CVE-2026-45409 |
中危 |
3.4 |
3.15 |
python-idna: idna: Denial of Service via specially crafted long inputs
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-45409
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-06-05 23:16 修改: 2026-07-23 07:10
|
| certifi |
CVE-2024-39689 |
低危 |
2022.9.24 |
2024.7.4 |
python-certifi: Remove root certificates from `GLOBALTRUST` from the root store
漏洞详情: https://avd.aquasec.com/nvd/cve-2024-39689
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2024-07-05 19:15 修改: 2026-06-17 07:42
|
| cryptography |
CVE-2026-34073 |
低危 |
38.0.1 |
46.0.6 |
python-cryptography: Cryptography: Security bypass due to improper DNS name constraint validation
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-34073
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2026-03-31 03:15 修改: 2026-06-17 10:38
|
| pip |
CVE-2026-1703 |
低危 |
22.0.4 |
26.0 |
pip: pip: Information disclosure via path traversal when installing crafted wheel archives
漏洞详情: https://avd.aquasec.com/nvd/cve-2026-1703
镜像层: sha256:ddf2ea8997bb4bb9b003e9f5b21215786a971359b97f9ce6e9902ec575a5e21d
发布日期: 2026-02-02 15:16 修改: 2026-06-17 10:16
|
| cryptography |
GHSA-5cpq-8wj7-hf2v |
低危 |
38.0.1 |
41.0.0 |
Vulnerable OpenSSL included in cryptography wheels
漏洞详情: https://github.com/advisories/GHSA-5cpq-8wj7-hf2v
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2023-06-02 17:13 修改: 2023-06-02 17:13
|
| cryptography |
GHSA-jm77-qphf-c4w8 |
低危 |
38.0.1 |
41.0.3 |
pyca/cryptography's wheels include vulnerable OpenSSL
漏洞详情: https://github.com/advisories/GHSA-jm77-qphf-c4w8
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2023-08-01 22:34 修改: 2023-08-01 22:34
|
| cryptography |
GHSA-v8gr-m533-ghj9 |
低危 |
38.0.1 |
41.0.4 |
Vulnerable OpenSSL included in cryptography wheels
漏洞详情: https://github.com/advisories/GHSA-v8gr-m533-ghj9
镜像层: sha256:e93b214f372b18a4b07dd1b623d18bdf6d3c30606afdd21dc8f25626214f15c9
发布日期: 2023-09-21 17:07 修改: 2023-09-21 17:07
|