Known vulnerabilities in python3.12 (Red Hat package)
Vendor:
Red Hat Inc.
Software:
python3.12 (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:python3_12_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
14
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.12.1-4.el9_4.14
3.12.9-1.el9_6.9
3.12.13-3.el8_10
3.12.13-3.el9_8.1
3.12.12-6.el9_8
3.12.1-4.el9_4.13
3.12.13-2.el8_10
3.12.12-4.el9_7.3
3.12.9-2.el10_0.8
3.12.12-4.el9_7.2
3.12.12-4.el8_10
3.12.12-3.el10_1.2
3.12.1-4.el9_4.11
3.12.9-2.el10_0.7
3.12.9-1.el9_6.6
3.12.12-3.el8_10
3.12.12-4.el9_7.1
3.12.9-1.el9_6.5
3.12.1-4.el9_4.10
3.12.9-2.el10_0.6
3.12.12-3.el10_1
3.12.9-1.el9_6.4
3.12.1-4.el9_4.9
3.12.12-4.el9_7
3.12.9-1.el9_6.3
3.12.1-4.el9_4.8
3.12.9-2.el10_0.4
3.12.12-1.el8_10
3.12.12-1.el10_1
3.12.9-1.el9
3.12.1-4.el9_4.7
3.12.9-2.el10_0.2
3.12.9-1.el9_6.1
3.12.11-1.el8_10
3.12.1-4.el9_4.6
3.12.5-2.el9_5.3
Vulnerabilities (14)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU122819 - Command injection CVE-2025-15367 |
CWE-77 | Medium | 3.12.1-4.el9_4.11, 3.12.9-1.el9_6.6, 3.12.9-2.el10_0.7, 3.12.12-3.el8_10, 3.12.12-4.el9_7.1 | 13.02.2026 |
SB2026021343 SB2026021347 SB2026021348 and 56 more |
||
| #VU122818 - Command injection CVE-2025-15366 |
CWE-77 | Medium | 3.12.1-4.el9_4.11, 3.12.9-1.el9_6.6, 3.12.9-2.el10_0.7, 3.12.12-3.el8_10, 3.12.12-4.el9_7.1 | 13.02.2026 |
SB2026021343 SB2026021347 SB2026021348 and 52 more |
||
| #VU122817 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2026-1299 |
CWE-93 | Medium | 3.12.1-4.el9_4.11, 3.12.9-1.el9_6.6, 3.12.9-2.el10_0.7, 3.12.12-3.el8_10, 3.12.12-4.el9_7.1 | 13.02.2026 |
SB2026021343 SB2026021347 SB2026021348 and 46 more |
||
| #VU122815 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-0865 |
CWE-444 | Medium | 3.12.12-3.el8_10, 3.12.12-6.el9_8 | 13.02.2026 |
SB2026021343 SB2026021347 SB2026021348 and 50 more |
||
| #VU119238 - Inefficient Algorithmic Complexity CVE-2025-12084 |
CWE-407 | Low | 3.12.1-4.el9_4.9, 3.12.9-1.el9_6.4, 3.12.9-2.el10_0.6, 3.12.12-1.el8_10, 3.12.12-3.el10_1, 3.12.12-4.el9_7 | 06.12.2025 |
SB2025120606 SB20251226352 SB2025123104 and 48 more |
||
| #VU119233 - Resource exhaustion CVE-2025-13836 |
CWE-400 | Medium | 3.12.1-4.el9_4.10, 3.12.9-1.el9_6.5, 3.12.9-2.el10_0.6, 3.12.12-3.el10_1, 3.12.12-4.el9_7 | 06.12.2025 |
SB2025120602 SB20251226352 SB2025123104 and 36 more |
||
| #VU116971 - Improper input validation CVE-2025-8291 |
CWE-20 | Medium | 3.12.1-4.el9_4.8, 3.12.9-1.el9_6.3, 3.12.9-2.el10_0.4, 3.12.12-1.el8_10, 3.12.12-1.el10_1 | 14.10.2025 |
SB2025101418 SB2025101423 SB2025101424 and 47 more |
||
| #VU113738 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2025-8194 |
CWE-835 | Medium | 3.12.1-4.el9_4.7 | 07.08.2025 |
SB2025080731 SB2025080738 SB2025080739 and 93 more |
||
| #VU111970 - Expected Behavior Violation CVE-2025-4435 |
CWE-440 | Low | 3.12.1-4.el9_4.6, 3.12.9-1.el9_6.1, 3.12.9-2.el10_0.2, 3.12.11-1.el8_10 | 26.06.2025 |
SB2025062630 SB2025062633 SB2025062634 and 59 more |
||
| #VU111969 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-12718 |
CWE-22 | Medium | 3.12.1-4.el9_4.6, 3.12.9-1.el9_6.1, 3.12.9-2.el10_0.2, 3.12.11-1.el8_10 | 26.06.2025 |
SB2025062630 SB2025062633 SB2025062634 and 62 more |
||
| #VU111968 - Improper Link Resolution Before File Access ('Link Following') CVE-2025-4138 |
CWE-59 | High | 3.12.1-4.el9_4.6, 3.12.9-1.el9_6.1, 3.12.9-2.el10_0.2, 3.12.11-1.el8_10 | 26.06.2025 |
SB2025062630 SB2025062633 SB2025062634 and 64 more |
||
| #VU111967 - Improper Link Resolution Before File Access ('Link Following') CVE-2025-4330 |
CWE-59 | High | 3.12.1-4.el9_4.6, 3.12.9-1.el9_6.1, 3.12.9-2.el10_0.2, 3.12.11-1.el8_10 | 26.06.2025 |
SB2025062630 SB2025062633 SB2025062634 and 63 more |
||
| #VU111966 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-4517 |
CWE-22 | High | 3.12.1-4.el9_4.6, 3.12.9-1.el9_6.1, 3.12.9-2.el10_0.2, 3.12.11-1.el8_10 | 26.06.2025 |
SB2025062630 SB2025062633 SB2025062634 and 77 more |
||
| #VU96945 - Resource exhaustion CVE-2024-7592 |
CWE-400 | Medium | 3.12.5-2.el9_5.3 | 09.09.2024 |
SB2024090916 SB2024090917 SB2024090918 and 72 more |