Miss Islington (bot)
160 exploits
Active since Jun 2019
pkgutil.get_data() does not enforce documented restrictions
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
CVSS 7.1
Python CPython - HTTP Header Injection
CPython < 3.15.0a7 - Unprotected User Data Exposure via SourcelessFileLoader Import Hook
Incomplete control character validation in http.cookies
CVSS 7.5
Stack overflow parsing XML with deeply nested DTD content models
CVSS 7.5
webbrowser.open() allows leading dashes in URLs
CVSS 3.3
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
CVSS 8.1
BaseCookie.js_output() does not neutralize embedded characters
CVSS 6.1
CPython < 3.15.0a7 - Unprotected User Data Exposure via SourcelessFileLoader Import Hook
CPython Tarfile Archive Misinterpretation via AREGTYPE Block Normalization
CVSS 3.3
Incomplete control character validation in http.cookies
CVSS 7.5
pkgutil.get_data() does not enforce documented restrictions
HTTP client proxy tunnel headers not validated for CR/LF
Base64 decoding stops at first padded quad by default
BaseCookie.js_output() does not neutralize embedded characters
CVSS 6.1
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVSS 7.5
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVSS 7.5
Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
CVSS 8.1
Stack overflow parsing XML with deeply nested DTD content models
CVSS 7.5
CPython < 3.15.0a7 - Unprotected User Data Exposure via SourcelessFileLoader Import Hook
Python <3.10.14-3.13.0a5 - Memory Corruption
CVSS 7.4
Python urllib.parse - Bracketed Host Validation Server-Side Request Forgery
CVSS 3.7
CPython 3.12.0-3.12.8, 3.13.0-3.13.1, 3.14.0a1-3.14.0a2 - Resource Consumption in asyncio
CVSS 7.5