Miss Islington (bot)
160 exploits
Active since Jun 2019
CPython - Zip File Path Traversal
CPython urllib.parse - Bracketed Host Validation Bypass
Python < 3.13.10 - Denial of Service via plistlib Malicious File Size Handling
CVSS 5.5
CPython Email Header Injection via Address List Folding
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
webbrowser.open() allows leading dashes in URLs
CVSS 3.3
CPython < 3.8.20 - Denial of Service via TarFile Header Parsing ReDoS
CVSS 7.5
CPython < 3.8.20 - Inefficient Regular Expression Complexity in http.cookies Module
CVSS 7.5
CPython < 3.9.21 - Command Injection via Unquoted Path in venv Module
CVSS 7.8
Python < 3.13.11 - Uncontrolled Resource Consumption via HTTP Response Content-Length
CVSS 7.5
Python < 3.13.10 - Denial of Service via plistlib Malicious File Size Handling
CVSS 5.5
Python urllib.request - Data URL Header Injection
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
CPython HTTP Header Injection via http.cookies.Morsel
CPython email module - CRLF Injection in BytesGenerator Header Serialization
CPython - Info Disclosure
CPython < 3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.5, 3.14.0a1-3.14.0b2 - DoS via HTML Parser
CVSS 4.3
CPython TarFile Extraction Infinite Loop Vulnerability
CVSS 7.5
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
CPython HTTP Header Injection via http.cookies.Morsel
CPython TarFile Extraction Infinite Loop Vulnerability
CVSS 7.5
webbrowser.open() allows leading dashes in URLs
CVSS 3.3
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
CVSS 7.1
CPython HTTP Header Injection via http.cookies.Morsel
CPython < 3.15.0a7 - Unprotected User Data Exposure via SourcelessFileLoader Import Hook