Miss Islington (bot)
125 exploits
Active since Jun 2019
Python < 3.13.10 - Denial of Service via plistlib Malicious File Size Handling
CVSS 5.5
Python urllib.request - Data URL Header Injection
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
CPython HTTP Header Injection via http.cookies.Morsel
CPython email module - CRLF Injection in BytesGenerator Header Serialization
CPython - Info Disclosure
CPython < 3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.5, 3.14.0a1-3.14.0b2 - DoS via HTML Parser
CVSS 4.3
CPython TarFile Extraction Infinite Loop Vulnerability
CVSS 7.5
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
CPython HTTP Header Injection via http.cookies.Morsel
CPython TarFile Extraction Infinite Loop Vulnerability
CVSS 7.5
webbrowser.open() allows leading dashes in URLs
CVSS 3.3
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
CPython HTTP Header Injection via http.cookies.Morsel
CPython < 3.15.0a7 - Unprotected User Data Exposure via SourcelessFileLoader Import Hook
pkgutil.get_data() does not enforce documented restrictions
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
Python CPython - HTTP Header Injection
CPython < 3.15.0a7 - Unprotected User Data Exposure via SourcelessFileLoader Import Hook
Incomplete control character validation in http.cookies
CVSS 7.5
Stack overflow parsing XML with deeply nested DTD content models
CVSS 7.5
webbrowser.open() allows leading dashes in URLs
CVSS 3.3
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
BaseCookie.js_output() does not neutralize embedded characters
CVSS 6.1
CPython < 3.15.0a7 - Unprotected User Data Exposure via SourcelessFileLoader Import Hook