Stan Ulbrych
59 exploits
Active since Jun 2024
pkgutil.get_data() does not enforce documented restrictions
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
CVSS 8.1
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
CVSS 7.1
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
CVSS 7.1
Use-after-free in lzma.LZMADecompressor, bz2.BZ2Decompressor, and gzip.GzipFile after re-use under memory pressure
CVSS 8.1
pkgutil.get_data() does not enforce documented restrictions
Stack overflow parsing XML with deeply nested DTD content models
CVSS 7.5
Incomplete control character validation in http.cookies
CVSS 7.5
CPython < 3.9.24 and 3.10.0a1-3.10.0b1 - Buffer Over-read via SSLContext.set_npn_protocols()
CVSS 6.5