Bugs fixes in "python3.10"
| Origin | Bug number | Title | Date fixed |
|---|---|---|---|
| CVE | CVE-2026-4786 | Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser. | 2026-07-06 |
| CVE | CVE-2026-4519 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behav | 2026-07-06 |
| CVE | CVE-2026-4224 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stac | 2026-07-06 |
| CVE | CVE-2026-3644 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling | 2026-07-06 |
| CVE | CVE-2026-3276 | unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with | 2026-07-06 |
| CVE | CVE-2026-2297 | The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not | 2026-07-06 |
| CVE | CVE-2026-1502 | CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. | 2026-07-06 |
| CVE | CVE-2026-1299 | The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allow | 2026-07-06 |
| CVE | CVE-2025-69534 | Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled Assert | 2026-07-06 |
| CVE | CVE-2025-13462 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE | 2026-07-06 |
| CVE | CVE-2026-0865 | User-controlled header names and values containing newlines can allow injecting HTTP headers. | 2026-03-09 |
| CVE | CVE-2025-15367 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containin | 2026-03-09 |
| CVE | CVE-2025-15366 | The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containi | 2026-03-09 |
| CVE | CVE-2026-0865 | User-controlled header names and values containing newlines can allow injecting HTTP headers. | 2026-03-09 |
| CVE | CVE-2025-15367 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containin | 2026-03-09 |
| CVE | CVE-2025-15366 | The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containi | 2026-03-09 |
| CVE | CVE-2026-0865 | User-controlled header names and values containing newlines can allow injecting HTTP headers. | 2026-02-05 |
| CVE | CVE-2026-0672 | When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all contro | 2026-02-05 |
| CVE | CVE-2025-15367 | The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containin | 2026-02-05 |
| CVE | CVE-2025-15366 | The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containi | 2026-02-05 |
About
-
Send Feedback to @ubuntu_updates