Stan Ulbrych
59 exploits
Active since Jun 2024
Incomplete control character validation in http.cookies
CVSS 7.5
Stack overflow parsing XML with deeply nested DTD content models
CVSS 7.5
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
CVSS 8.1
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
CVSS 7.1
Python Software Foundation CPython - Potential DoS via Quadratic Complexity in unicodedata.normalize()
CPython bz2.BZ2Decompressor - Stack Buffer Overflow
tarfile extraction filter bypass allows escaping the destination directory
Python Software Foundation CPython - Tarfile Opened in Streaming Mode Mishandles EOF
tarfile.data_filter path traversal bypass allows writing outside the extraction directory
CPython bz2.BZ2Decompressor - Stack Buffer Overflow
Python Software Foundation CPython - Tarfile Opened in Streaming Mode Mishandles EOF
Python Software Foundation CPython - Tarfile Opened in Streaming Mode Mishandles EOF
Python Software Foundation CPython - Tarfile Opened in Streaming Mode Mishandles EOF
Python Software Foundation CPython - Tarfile Opened in Streaming Mode Mishandles EOF
Incomplete control character validation in http.cookies
CVSS 7.5
Python Software Foundation CPython - Tarfile Opened in Streaming Mode Mishandles EOF
Incomplete control character validation in http.cookies
CVSS 7.5
tarfile extraction filter bypass allows escaping the destination directory
Python Software Foundation CPython - Tarfile Opened in Streaming Mode Mishandles EOF
tarfile extraction filter bypass allows escaping the destination directory
tarfile extraction filter bypass allows escaping the destination directory
tarfile extraction filter bypass allows escaping the destination directory
tarfile extraction filter bypass allows escaping the destination directory
The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
CVSS 7.5
CPython bz2.BZ2Decompressor - Stack Buffer Overflow