Known vulnerabilities in python3.11-pulpcore (Red Hat package)
Vendor:
Red Hat Inc.
Software:
python3.11-pulpcore (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:python3_11-pulpcore_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
18
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (18)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU120990 - Improper Handling of Highly Compressed Data (Data Amplification) CVE-2025-69223 |
CWE-409 | Medium | 3.49.49-1.el9ap | 06.01.2026 |
SB2026010643 SB2026012661 SB2026012855 and 15 more |
||
| #VU119235 - Resource exhaustion CVE-2025-61729 |
CWE-400 | Medium | 3.49.49-1.el9ap | 06.12.2025 |
SB2025120604 SB20251210172 SB20251210173 and 146 more |
||
| #VU119231 - Resource exhaustion CVE-2025-66471 |
CWE-400 | Medium | 3.49.49-1.el9ap | 05.12.2025 |
SB2025120581 SB2025121208 SB2026011313 and 88 more |
||
| #VU119043 - Resource Management Errors CVE-2025-64460 |
CWE-399 | Medium | 3.49.49-1.el9ap | 02.12.2025 |
SB2025120234 SB2025120237 SB2025120561 and 13 more |
||
| #VU116913 - Reachable Assertion CVE-2025-59530 |
CWE-617 | Medium | 3.28.37-2.el8ap, 3.28.37-2.el9ap | 13.10.2025 |
SB2025101341 SB2025111857 SB2025111935 and 3 more |
||
| #VU113069 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-53643 |
CWE-444 | Medium | 3.49.49-1.el9ap | 18.07.2025 |
SB2025071857 SB2025090377 SB2025091303 and 15 more |
||
| #VU112882 - Uncontrolled Recursion CVE-2025-4565 |
CWE-674 | Medium | 3.49.49-1.el9ap | 14.07.2025 |
SB2025071429 SB2025071430 SB2025071431 and 21 more |
||
| #VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-22871 |
CWE-444 | Medium | 3.49.42-1.el8ap, 3.49.42-1.el9ap | 05.04.2025 |
SB2025040507 SB2025040508 SB2025040739 and 109 more |
||
| #VU105388 - Improper input validation CVE-2025-26699 |
CWE-20 | Medium | 3.49.34-1.el8ap, 3.49.34-1.el9ap | 06.03.2025 |
SB2025030630 SB2025030734 SB2025030802 and 19 more |
||
| #VU105387 - Improper input validation CVE-2025-27516 |
CWE-20 | Low | 3.49.34-1.el8ap, 3.49.34-1.el9ap | 06.03.2025 |
SB2025030628 SB2025031001 SB2025031002 and 83 more |
||
| #VU103000 - Improper input validation CVE-2024-56374 |
CWE-20 | Medium | 3.49.30-1.el8ap, 3.49.30-1.el9ap | 20.01.2025 |
SB2025012005 SB2025012029 SB2025012030 and 11 more |
||
| #VU102463 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2024-55565 |
CWE-835 | Medium | 3.49.29-1.el8ap, 3.49.29-1.el9ap | 08.01.2025 |
SB2025010849 SB2025010851 SB2025010853 and 45 more |
||
| #VU101972 - Security Features CVE-2024-56326 |
CWE-254 | Low | 3.49.30-1.el8ap, 3.49.30-1.el9ap | 27.12.2024 |
SB2024122789 SB2024122790 SB2024122791 and 78 more |
||
| #VU101971 - Security Features CVE-2024-56201 |
CWE-254 | Low | 3.49.30-1.el8ap, 3.49.30-1.el9ap | 27.12.2024 |
SB2024122789 SB2025010203 SB2025010322 and 62 more |
||
| #VU101889 - Improper input validation CVE-2024-11407 |
CWE-20 | Medium | 3.49.29-1.el8ap, 3.49.29-1.el9ap | 20.12.2024 |
SB2024122036 SB2024122046 SB2024122057 and 10 more |
||
| #VU101276 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-53908 |
CWE-89 | High | 3.49.29-1.el8ap, 3.49.29-1.el9ap | 05.12.2024 |
SB2024120536 SB2024120537 SB2024120538 and 15 more |
||
| #VU101275 - Resource exhaustion CVE-2024-53907 |
CWE-400 | Medium | 3.49.29-1.el8ap, 3.49.29-1.el9ap, 3.49.30-1.el8ap, 3.49.30-1.el9ap | 05.12.2024 |
SB2024120536 SB2024120537 SB2024120538 and 18 more |
||
| #VU100600 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2024-52304 |
CWE-444 | Medium | 3.49.29-1.el8ap, 3.49.29-1.el9ap | 19.11.2024 |
SB2024111901 SB2024111916 SB2024111917 and 19 more |