Seth Michael Larson
113 exploits
Active since Mar 2020
CPython < 3.8.20 - Denial of Service via TarFile Header Parsing ReDoS
CVSS 7.5
CPython urllib.parse - Bracketed Host Validation Bypass
CPython HTTP Header Injection via Email Header Folding
Python urllib.request - Data URL Header Injection
CPython < 3.15.0a6 - Command Injection via IMAP Command Newline Injection
CPython < 3.15.0a6 - Command Injection via Newline in POP3 Command
CPython Path Traversal via TarFile Extraction Filter Bypass
CVSS 7.5
CPython TarFile - Incorrect Extraction with errorlevel=0
CVSS 7.5
urllib3 < 2.5.0 - Open Redirect via PoolManager Retry Configuration
CVSS 5.3
CPython HTTP Header Injection via http.cookies.Morsel
Python CPython - HTTP Header Injection
CPython email module - CRLF Injection in BytesGenerator Header Serialization
pip < 26.0 - Path Traversal via Maliciously Crafted Wheel Archive