Debian Pypy3 vulnerabilities
60 known vulnerabilities affecting debian/pypy3.
Total CVEs
60
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH19MEDIUM25LOW11
Vulnerabilities
Page 3 of 3
CVE-2024-12718P4LOWCVSS 5.3fixed in pypy3 7.3.20+dfsg-2 (forky)2024
CVE-2024-12718 [MEDIUM] CVE-2024-12718: jython - Allows modifying some file metadata (e.g. last modified) with filter="data" or f...
Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extraction directory. You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of "data" or
debian
CVE-2021-3426P4MEDIUMCVSS 5.7fixed in pypy3 7.3.3+dfsg-4 (bookworm)2021
CVE-2021-3426 [MEDIUM] CVE-2021-3426: pypy3 - There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers o...
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw
debian
CVE-2021-4189P4MEDIUMCVSS 5.3fixed in pypy3 7.3.5+dfsg-2 (bookworm)2021
CVE-2021-4189 [MEDIUM] CVE-2021-4189: pypy3 - A flaw was found in Python, specifically in the FTP (File Transfer Protocol) cli...
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead
debian
CVE-2026-0865P4MEDIUMCVSS 5.9fixed in python3.13 3.13.12-1 (forky)2026
CVE-2026-0865 [MEDIUM] CVE-2026-0865: jython - User-controlled header names and values containing newlines can allow injecting ...
User-controlled header names and values containing newlines can allow injecting HTTP headers.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2023-40217P4MEDIUMCVSS 5.3fixed in pypy3 7.3.11+dfsg-2+deb12u2 (bookworm)2023
CVE-2023-40217 [MEDIUM] CVE-2023-40217: pypy3 - An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x bef...
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance wi
debian
CVE-2025-12084P4MEDIUMCVSS 6.3fixed in python3.13 3.13.11-1 (forky)2025
CVE-2025-12084 [MEDIUM] CVE-2025-12084: jython - When building nested elements using xml.dom.minidom methods such as appendChild(...
When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Availability can be impacted when building excessively nested documents.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2025-11468P4LOWCVSS 5.7fixed in python3.13 3.13.12-1 (forky)2025
CVE-2025-11468 [MEDIUM] CVE-2025-11468: jython - When folding a long comment in an email header containing exclusively unfoldable...
When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2022-48564P4MEDIUMCVSS 6.5fixed in pypy3 7.3.5+dfsg-2 (bookworm)2022
CVE-2022-48564 [MEDIUM] CVE-2022-48564: pypy3 - read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential Do...
read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.
Scope: local
bookworm: resolved (fixed in 7.3.5+dfsg-2)
bullseye: resolved (fixed in 7.3.5+dfsg-2)
forky: resolved (fixed in 7.3.5+dfsg-2)
sid: resolved (fixed in 7.3.5+dfsg-2)
trixi
debian
CVE-2022-48566P4MEDIUMCVSS 5.9fixed in pypy3 7.3.5+dfsg-2 (bookworm)2022
CVE-2022-48566 [MEDIUM] CVE-2022-48566: pypy3 - An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1...
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
Scope: local
bookworm: resolved (fixed in 7.3.5+dfsg-2)
bullseye: resolved (fixed in 7.3.5+dfsg-2)
forky: resolved (fixed in 7.3.5+dfsg-2)
sid: resolved (fixed in 7.3.5+dfsg-2)
trixi
debian
CVE-2024-6923P4MEDIUMCVSS 5.5fixed in pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)2024
CVE-2024-6923 [MEDIUM] CVE-2024-6923: pypy3 - There is a MEDIUM severity vulnerability affecting CPython. The email module d...
There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.3.5+dfsg-2+deb11u5)
forky: resolved (fixed in 7.3.18+dfsg-1)
sid: resolved (fixed in 7.3.18+
debian
CVE-2024-0450P4MEDIUMCVSS 6.2fixed in pypy3 7.3.11+dfsg-2+deb12u2 (bookworm)2024
CVE-2024-0450 [MEDIUM] CVE-2024-0450: pypy3 - An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3....
An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in t
debian
CVE-2026-2297P4MEDIUMCVSS 5.7fixed in python3.14 3.14.3-4 (sid)2026
CVE-2026-2297 [MEDIUM] CVE-2026-2297: pypy3 - The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader...
The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2025-4516P4LOWCVSS 5.9fixed in python3.13 3.13.3-4 (forky)2025
CVE-2025-4516 [MEDIUM] CVE-2025-4516: pypy3 - There is an issue in CPython when using `bytes.decode("unicode_escape", error="i...
There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using the "unicode_escape" encoding or an error handler your usage is not affected. To work-around this issue you may stop using the error= handler and instead wrap the bytes.decode() call in a try-except catching the DecodeError.
Scope: local
bookworm: res
debian
CVE-2025-6075P4LOWCVSS 1.8fixed in python3.13 3.13.11-1 (forky)2025
CVE-2025-6075 [LOW] CVE-2025-6075: pypy3 - If the value passed to os.path.expandvars() is user-controlled a performance de...
If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2025-8291P4MEDIUMCVSS 4.3fixed in pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)2025
CVE-2025-8291 [MEDIUM] CVE-2025-8291: jython - The 'zipfile' module would not check the validity of the ZIP64 End of Central Di...
The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be abused to create ZIP archives that are handled differently by the 'zipfile' module compa
debian
CVE-2025-13837P4LOWCVSS 2.1fixed in python3.13 3.13.11-1 (forky)2025
CVE-2025-13837 [LOW] CVE-2025-13837: pypy3 - When loading a plist file, the plistlib module reads data in size specified by t...
When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2025-6069P4MEDIUMCVSS 4.3fixed in pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)2025
CVE-2025-6069 [MEDIUM] CVE-2025-6069: jython - The html.parser.HTMLParser class had worse-case quadratic complexity when proces...
The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2024-11168P4MEDIUMCVSS 6.3fixed in pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)2024
CVE-2024-11168 [MEDIUM] CVE-2024-11168: pypy3 - The urllib.parse.urlsplit() and urlparse() functions improperly validated bracke...
The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.3.5+dfsg-2+deb11u5)
forky: resolved (fi
debian
CVE-2026-4519P4HIGHCVSS 7.0fixed in python3.14 3.14.4-1 (sid)2026
CVE-2026-4519 [HIGH] CVE-2026-4519: jython - The webbrowser.open() API would accept leading dashes in the URL which could be...
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
debian
CVE-2025-1795P4LOWCVSS 2.3fixed in pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)2025
CVE-2025-1795 [LOW] CVE-2025-1795: pypy3 - During an address list folding when a separating comma ends up on a folded line ...
During an address list folding when a separating comma ends up on a folded line and that line is to be unicode-encoded then the separator itself is also unicode-encoded. Expected behavior is that the separating comma remains a plan comma. This can result in the address header being misinterpreted by some mail servers.
Scope: local
bookworm: open
bullseye: resolved (fixed
debian
← Previous3 / 3