Serhiy Storchaka
129 exploits
Active since Oct 2020
CPython - Info Disclosure
Python <3.14 - Path Traversal
CVSS 9.4
CPython < 3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.5, 3.14.0a1-3.14.0b2 - DoS via HTML Parser
CVSS 4.3
os.path.expandvars - Info Disclosure
CVSS 5.5
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
CPython < 3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.5, 3.14.0a1-3.14.0b2 - DoS via HTML Parser
CVSS 4.3
os.path.expandvars - Info Disclosure
CVSS 5.5
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
Base64 decoding stops at first padded quad by default
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVSS 7.5
Base64 decoding stops at first padded quad by default
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVSS 7.5
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVSS 7.5
Base64 decoding stops at first padded quad by default
Python 3.0.0-3.9.0 - Remote Code Execution via CJK Codec Test HTTP Content
CVSS 9.8
CPython <3.12.1-3.8.18 - Use After Free
CVSS 7.8
CPython Zip Bomb Asymmetric Resource Consumption
CVSS 6.2
CPython HTTP Header Injection in email Module
CVSS 5.5
CPython < 3.8.20 - Inefficient Regular Expression Complexity in http.cookies Module
CVSS 7.5
Python < 3.13.10 - Incorrect Type Conversion in base64 Decode Functions
CVSS 5.3
Python < 3.13.11 - Uncontrolled Resource Consumption via HTTP Response Content-Length
CVSS 7.5
Python < 3.13.10 - Denial of Service via plistlib Malicious File Size Handling
CVSS 5.5
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
CPython TarFile - Incorrect Extraction with errorlevel=0
CVSS 7.5