Skip to content

Several python CVEs in 3.14.6 #215

Description

@daveatsbb

We are using your latest nightly build (https://www.cloudbase.it/downloads/CloudbaseInitSetup_x64.msi).
Our vulnerability scanner reports several python vulnerabilities at our Windows Servers:

CVE-2025-15366 - Python CPython up to 3.14.x Imaplib command injection
CVE-2026-0864 - Python CPython up to 3.14.x Configuration injection
CVE-2026-11940 - Python CPython up to 3.14.x Archive tarfile.extractall path traversal
CVE-2026-11972 - Python CPython up to 3.15.x Tarfile return value
CVE-2026-12003 - Python CPython up to 3.14.x on Windows Installation Directory Modules/setup.local VPATH uncontrolled search path
CVE-2026-15308 - Python up to 3.14.x Incremental HTML Parser HTMLParser denial of service
CVE-2026-18503 - Python up to 3.15.x csv csv.py csv.Sniffer.sniff csv injection
CVE-2026-19672 - Python tarfile up to 3.15.x path traversal
CVE-2026-4360 - Python CPython up to 3.14.x Tarfile.extract filter permissions
CVE-2026-6879 - PSF Python up to 3.14.x XPath Element.findall/Element.iterfind/Element.find resource consumption

Solution is to update python to 3.14.7. When can we expect an update?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions