Výsledky hledání

výrobce: Python× v celém archivu zrušit filtry

7 karet z 9 položek CZ · EN/orig

SPOJENO PŘES CVE Risolte vulnerabilità in CPython

Aggiornamenti di sicurezza risolvono 2 vulnerabilità, di cui 1 con gravità "critica" e 1 con gravità "alta", in CPython, implementazione di riferimento open source del linguaggio di programmazione Python. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato remoto non autenticato di eludere i meccanismi di sicurezza o di compromettere la disponibilità del servizio sui sistemi interessati.

EPSS 0.01 CVSS 9.2 CVE-2026-19445 CVE-2026-19553 Python CPython IT FI FR

tg: zranitelnost tp: DDoS

· CSIRT Itálie (ACN) · Risolte vulnerabilità in CPython · zachyceno · NCSC-FI · CRITICAL severity vulnerability affecting CPython · zachyceno · CERT-FR – avis · Multiples vulnérabilités dans CPython (01 octobre 2026)

· zachyceno

The Truth about GET and HTTP Standards, (Tue, Sep 22nd)

On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow "GET" requests that include a body. The main reason for this was that GET requests typically do not contain a body. But what if they do? I did a quick check of a couple of common web servers I had handy, to see what would happen: Apache For this test, I ran Apache 2.4.68 on a Mac. It happily accepted a body with a GET request: % nc -c localhost 8080 GET /cgi-bin/test-cgi HTTP/1.1 Host:…

Apache NGINX Python US

tg: rozbor

· SANS Internet Storm Ctr. · The Truth about GET and HTTP Standards, (Tue, Sep 22nd)

· zachyceno

· zachyceno

· zachyceno

CVE-2023-27043 The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.

Information published.

EPSS 0.03 CVE-2023-27043 Python US

· Microsoft Security · CVE-2023-27043 The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.