Known vulnerabilities in Python 3.14.0a7

Vendor: Python.org
Software: Python
Version: 3.14.0a7
Software CPE: cpe:2.3:a:python_org:python:*:*:*:*:*:*:*:*
Total vulnerabilities: 17
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Python version 3.14.0a7 Python 3.14.0a7 is affected by 17 vulnerabilities: 3 high, 10 medium, 4 low Critical High Medium Low

Vulnerabilities (17)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU124221 - Uncontrolled Recursion
CVE-2026-4224
CWE-674 Medium
No
No
- 23.03.2026 SB2026032343
SB2026090932
#VU122976 - Type conversion
CVE-2025-12781
CWE-704 Low
No
No
3.13.12, 3.14.1, 3.15.0a2 17.02.2026 SB2026021706
SB2026021715
SB2026021716
and 4 more
#VU122817 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2026-1299
CWE-93 Medium
No
No
3.13.12, 3.14.3, 3.15.0a6 13.02.2026 SB2026021343
SB2026021347
SB2026021348
and 46 more
#VU122816 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2025-15282
CWE-93 Medium
No
No
3.13.12, 3.14.3, 3.15.0a6 13.02.2026 SB2026021343
SB2026021353
SB2026021354
and 25 more
#VU122815 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-0865
CWE-444 Medium
No
No
3.13.12, 3.14.3, 3.15.0a6 13.02.2026 SB2026021343
SB2026021347
SB2026021348
and 50 more
#VU122814 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2026-0672
CWE-93 Medium
No
No
3.13.12, 3.14.3, 3.15.0a6 13.02.2026 SB2026021343
SB2026021353
SB2026021354
and 30 more
#VU122813 - Improper input validation
CVE-2025-11468
CWE-20 Medium
No
No
3.13.12, 3.14.3, 3.15.0a6 13.02.2026 SB2026021343
SB2026021353
SB2026021354
and 25 more
#VU119238 - Inefficient Algorithmic Complexity
CVE-2025-12084
CWE-407 Low
No
No
3.13.11, 3.14.2 06.12.2025 SB2025120606
SB20251226352
SB2025123104
and 48 more
#VU119234 - Resource exhaustion
CVE-2025-13837
CWE-400 Medium
No
No
3.13.10, 3.14.1 06.12.2025 SB2025120603
SB20251226352
SB2025123104
and 13 more
#VU119233 - Resource exhaustion
CVE-2025-13836
CWE-400 Medium
No
No
3.13.11, 3.14.1 06.12.2025 SB2025120602
SB20251226352
SB2025123104
and 36 more
#VU118735 - Resource exhaustion
CVE-2025-6075
CWE-400 Low
No
No
3.9.25, 3.15.0a2 24.11.2025 SB2025112495
SB2025112498
SB2025112569
and 26 more
#VU112030 - Use After Free
CVE-2025-4516
CWE-416 Medium
No
No
3.9.23, 3.10.18, 3.11.13, 3.12.11, 3.13.4, 3.14.0b2 28.06.2025 SB2025062630
SB2025062802
SB2025062803
and 18 more
#VU111970 - Expected Behavior Violation
CVE-2025-4435
CWE-440 Low
No
No
3.9.23, 3.10.18, 3.11.13, 3.12.11, 3.13.4, 3.14.0 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 59 more
#VU111969 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-12718
CWE-22 Medium
No
No
3.9.23, 3.10.18, 3.11.13, 3.12.11, 3.13.4, 3.14.0 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 62 more
#VU111968 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-4138
CWE-59 High
Public exploit available
No
3.9.23, 3.10.18, 3.11.13, 3.12.11, 3.13.4, 3.14.0 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 64 more
#VU111967 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-4330
CWE-59 High
No
No
3.9.23, 3.10.18, 3.11.13, 3.12.11, 3.13.4, 3.14.0 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 63 more
#VU111966 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-4517
CWE-22 High
Public exploit available
No
3.9.23, 3.10.18, 3.11.13, 3.12.11, 3.13.4, 3.14.0 26.06.2025 SB2025062630
SB2025062633
SB2025062634
and 77 more