Serhiy Storchaka
140 exploits
Active since Oct 2020
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
CPython TarFile - Incorrect Extraction with errorlevel=0
CVSS 7.5
CPython - Info Disclosure
Python <3.14 - Path Traversal
CVSS 9.4
CPython < 3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.5, 3.14.0a1-3.14.0b2 - DoS via HTML Parser
CVSS 4.3
os.path.expandvars - Info Disclosure
CVSS 5.5
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
CPython TarFile - Incorrect Extraction with errorlevel=0
CVSS 7.5
CPython - Info Disclosure
Python <3.14 - Path Traversal
CVSS 9.4
CPython < 3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.5, 3.14.0a1-3.14.0b2 - DoS via HTML Parser
CVSS 4.3
os.path.expandvars - Info Disclosure
CVSS 5.5
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
CPython < 3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.5, 3.14.0a1-3.14.0b2 - DoS via HTML Parser
CVSS 4.3
os.path.expandvars - Info Disclosure
CVSS 5.5
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
CPython <3.9.24, 3.10.0-3.10.18, 3.11.0-3.11.13, 3.12.0-3.12.11, 3.13.0-3.13.9, 3.14.0 - ZIP64 EOCD Validation Bypass
CVSS 4.3
Base64 decoding stops at first padded quad by default
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVSS 7.5
Base64 decoding stops at first padded quad by default
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVSS 7.5
shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs
CVSS 7.5