cbcvebase.

Debian Pypy3 vulnerabilities

60 known vulnerabilities affecting debian/pypy3.

Total CVEs
60
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH19MEDIUM25LOW11

Vulnerabilities

Page 3 of 3
CVE-2024-12718P4LOWCVSS 5.3fixed in pypy3 7.3.20+dfsg-2 (forky)2024
CVE-2024-12718 [MEDIUM] CVE-2024-12718: jython - Allows modifying some file metadata (e.g. last modified) with filter="data" or f... Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extraction directory. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or
debian
CVE-2021-3426P4MEDIUMCVSS 5.7fixed in pypy3 7.3.3+dfsg-4 (bookworm)2021
CVE-2021-3426 [MEDIUM] CVE-2021-3426: pypy3 - There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers o... There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw
debian
CVE-2021-4189P4MEDIUMCVSS 5.3fixed in pypy3 7.3.5+dfsg-2 (bookworm)2021
CVE-2021-4189 [MEDIUM] CVE-2021-4189: pypy3 - A flaw was found in Python, specifically in the FTP (File Transfer Protocol) cli... A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead
debian
CVE-2026-0865P4MEDIUMCVSS 5.9fixed in python3.13 3.13.12-1 (forky)2026
CVE-2026-0865 [MEDIUM] CVE-2026-0865: jython - User-controlled header names and values containing newlines can allow injecting ... User-controlled header names and values containing newlines can allow injecting HTTP headers. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-40217P4MEDIUMCVSS 5.3fixed in pypy3 7.3.11+dfsg-2+deb12u2 (bookworm)2023
CVE-2023-40217 [MEDIUM] CVE-2023-40217: pypy3 - An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x bef... An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance wi
debian
CVE-2025-12084P4MEDIUMCVSS 6.3fixed in python3.13 3.13.11-1 (forky)2025
CVE-2025-12084 [MEDIUM] CVE-2025-12084: jython - When building nested elements using xml.dom.minidom methods such as appendChild(... When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2025-11468P4LOWCVSS 5.7fixed in python3.13 3.13.12-1 (forky)2025
CVE-2025-11468 [MEDIUM] CVE-2025-11468: jython - When folding a long comment in an email header containing exclusively unfoldable... When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2022-48564P4MEDIUMCVSS 6.5fixed in pypy3 7.3.5+dfsg-2 (bookworm)2022
CVE-2022-48564 [MEDIUM] CVE-2022-48564: pypy3 - read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential Do... read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format. Scope: local bookworm: resolved (fixed in 7.3.5+dfsg-2) bullseye: resolved (fixed in 7.3.5+dfsg-2) forky: resolved (fixed in 7.3.5+dfsg-2) sid: resolved (fixed in 7.3.5+dfsg-2) trixi
debian
CVE-2022-48566P4MEDIUMCVSS 5.9fixed in pypy3 7.3.5+dfsg-2 (bookworm)2022
CVE-2022-48566 [MEDIUM] CVE-2022-48566: pypy3 - An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1... An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest. Scope: local bookworm: resolved (fixed in 7.3.5+dfsg-2) bullseye: resolved (fixed in 7.3.5+dfsg-2) forky: resolved (fixed in 7.3.5+dfsg-2) sid: resolved (fixed in 7.3.5+dfsg-2) trixi
debian
CVE-2024-6923P4MEDIUMCVSS 5.5fixed in pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)2024
CVE-2024-6923 [MEDIUM] CVE-2024-6923: pypy3 - There is a MEDIUM severity vulnerability affecting CPython. The email module d... There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. Scope: local bookworm: open bullseye: resolved (fixed in 7.3.5+dfsg-2+deb11u5) forky: resolved (fixed in 7.3.18+dfsg-1) sid: resolved (fixed in 7.3.18+
debian
CVE-2024-0450P4MEDIUMCVSS 6.2fixed in pypy3 7.3.11+dfsg-2+deb12u2 (bookworm)2024
CVE-2024-0450 [MEDIUM] CVE-2024-0450: pypy3 - An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.... An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in t
debian
CVE-2026-2297P4MEDIUMCVSS 5.7fixed in python3.14 3.14.3-4 (sid)2026
CVE-2026-2297 [MEDIUM] CVE-2026-2297: pypy3 - The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader... The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2025-4516P4LOWCVSS 5.9fixed in python3.13 3.13.3-4 (forky)2025
CVE-2025-4516 [MEDIUM] CVE-2025-4516: pypy3 - There is an issue in CPython when using `bytes.decode("unicode_escape", error="i... There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError. Scope: local bookworm: res
debian
CVE-2025-6075P4LOWCVSS 1.8fixed in python3.13 3.13.11-1 (forky)2025
CVE-2025-6075 [LOW] CVE-2025-6075: pypy3 - If the value passed to os.path.expandvars() is user-controlled a performance de... If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2025-8291P4MEDIUMCVSS 4.3fixed in pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)2025
CVE-2025-8291 [MEDIUM] CVE-2025-8291: jython - The 'zipfile' module would not check the validity of the ZIP64 End of Central Di... The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compa
debian
CVE-2025-13837P4LOWCVSS 2.1fixed in python3.13 3.13.11-1 (forky)2025
CVE-2025-13837 [LOW] CVE-2025-13837: pypy3 - When loading a plist file, the plistlib module reads data in size specified by t... When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2025-6069P4MEDIUMCVSS 4.3fixed in pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)2025
CVE-2025-6069 [MEDIUM] CVE-2025-6069: jython - The html.parser.HTMLParser class had worse-case quadratic complexity when proces... The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2024-11168P4MEDIUMCVSS 6.3fixed in pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)2024
CVE-2024-11168 [MEDIUM] CVE-2024-11168: pypy3 - The urllib.parse.urlsplit() and urlparse() functions improperly validated bracke... The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser. Scope: local bookworm: open bullseye: resolved (fixed in 7.3.5+dfsg-2+deb11u5) forky: resolved (fi
debian
CVE-2026-4519P4HIGHCVSS 7.0fixed in python3.14 3.14.4-1 (sid)2026
CVE-2026-4519 [HIGH] CVE-2026-4519: jython - The webbrowser.open() API would accept leading dashes in the URL which could be... The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open(). Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2025-1795P4LOWCVSS 2.3fixed in pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)2025
CVE-2025-1795 [LOW] CVE-2025-1795: pypy3 - During an address list folding when a separating comma ends up on a folded line ... During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers. Scope: local bookworm: open bullseye: resolved (fixed
debian
Debian Pypy3 vulnerabilities | cvebase