Known vulnerabilities in python3 (Red Hat package)
Vendor:
Red Hat Inc.
Software:
python3 (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:python3_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
44
Public exploits:
3
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
3.6.8-78.el8_10
3.9.25-7.el9_8.3
3.6.8-21.el7_9.7
3.6.8-39.el8_4.12
3.6.8-47.el8_6.14
3.6.8-51.el8_8.16
3.9.25-7.el9_8.2
3.6.8-77.el8_10
3.6.8-21.el7_9.6
3.9.25-7.el9_8
3.6.8-39.el8_4.11
3.6.8-51.el8_8.15
3.6.8-47.el8_6.13
3.9.25-3.el9_7.3
3.6.8-76.el8_10
3.6.8-21.el7_9.5
3.6.8-39.el8_4.10
3.6.8-24.el8_2.7
3.6.8-51.el8_8.14
3.9.25-3.el9_7.2
3.6.8-75.el8_10
3.6.8-21.el7_9.4
3.6.8-51.el8_8.13
3.6.8-74.el8_10
3.9.25-3.el9_7.1
3.6.8-39.el8_4.9
3.6.8-24.el8_2.6
3.6.8-47.el8_6.11
3.6.8-21.el7_9.3
3.6.8-47.el8_6.10
3.6.8-51.el8_8.12
3.6.8-73.el8_10
3.6.8-72.el8_10
3.6.8-24.el8_2.5
3.9.25-3.el9_7
3.6.8-39.el8_4.8
3.9.25-2.el9_7
3.9.23-2.el9
3.6.8-24.el8_2.4
3.6.8-51.el8_8.11
3.6.8-39.el8_4.7
3.6.8-21.el7_9.2
3.6.8-47.el8_6.9
3.9.21-2.el9
3.9.21-2.el9_6.2
3.9.21-2.el9_6.1
3.6.8-51.el8_8.10
3.6.8-47.el8_6.8
3.6.8-70.el8_10
3.6.8-21.el7_9.1
3.6.8-69.el8_10
3.6.8-10.el7_7.1
3.6.8-47.el8_6.7
3.6.8-67.el8_10
3.6.8-39.el8_4.5
3.6.8-47.el8_6.6
3.6.8-24.el8_2.3
3.6.8-51.el8_8.6
3.6.8-62.el8_10
3.6.8-51.el8_8.4
3.6.8-47.el8_6.4
3.6.8-56.el8_9.3
3.6.8-56.el8_9
3.6.8-21.el7_9
3.6.8-39.el8_4.3
3.6.8-15.1.el8_1.2
3.6.8-51.el8_8.2
3.6.8-24.el8_2.2
3.6.8-47.el8_6.2
3.6.8-15.1.el8_1.1
3.6.8-24.el8_2.1
3.6.8-39.el8_4.2
3.6.8-47.el8_6.1
3.6.8-51.el8_8.1
3.6.8-19.el7_9
3.6.8-48.el8_7.1
3.6.8-41.el8
3.6.8-39.el8_4
3.6.8-47.el8_6
3.6.8-45.el8
3.6.8-24.el8_2
3.6.8-37.el8
3.6.8-18.el7
3.6.8-31.el8
3.6.8-17.el7
3.6.8-23.el8
3.6.8-13.el7
3.6.8-15.1.el8
3.6.8-2.el8_0
Vulnerabilities (44)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU122819 - Command injection CVE-2025-15367 |
CWE-77 | Medium | 3.6.8-21.el7_9.4, 3.6.8-24.el8_2.6, 3.6.8-39.el8_4.9, 3.6.8-47.el8_6.11, 3.6.8-51.el8_8.13, 3.6.8-73.el8_10 | 13.02.2026 |
SB2026021343 SB2026021347 SB2026021348 and 56 more |
||
| #VU122818 - Command injection CVE-2025-15366 |
CWE-77 | Medium | 3.6.8-21.el7_9.4, 3.6.8-24.el8_2.6, 3.6.8-39.el8_4.9, 3.6.8-47.el8_6.11, 3.6.8-51.el8_8.13, 3.6.8-73.el8_10 | 13.02.2026 |
SB2026021343 SB2026021347 SB2026021348 and 52 more |
||
| #VU122817 - Improper Neutralization of CRLF Sequences ('CRLF Injection') CVE-2026-1299 |
CWE-93 | Medium | 3.6.8-21.el7_9.4, 3.6.8-24.el8_2.6, 3.6.8-39.el8_4.9, 3.6.8-47.el8_6.11, 3.6.8-51.el8_8.13, 3.6.8-73.el8_10 | 13.02.2026 |
SB2026021343 SB2026021347 SB2026021348 and 46 more |
||
| #VU122815 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-0865 |
CWE-444 | Medium | 3.6.8-73.el8_10 | 13.02.2026 |
SB2026021343 SB2026021347 SB2026021348 and 49 more |
||
| #VU119238 - Inefficient Algorithmic Complexity CVE-2025-12084 |
CWE-407 | Low | 3.6.8-21.el7_9.3, 3.6.8-24.el8_2.5, 3.6.8-39.el8_4.8, 3.6.8-47.el8_6.10, 3.6.8-51.el8_8.12, 3.6.8-72.el8_10 | 06.12.2025 |
SB2025120606 SB20251226352 SB2025123104 and 48 more |
||
| #VU113738 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2025-8194 |
CWE-835 | Medium | 3.6.8-21.el7_9.2, 3.6.8-24.el8_2.4, 3.6.8-39.el8_4.7, 3.6.8-47.el8_6.9, 3.6.8-51.el8_8.11 | 07.08.2025 |
SB2025080731 SB2025080738 SB2025080739 and 93 more |
||
| #VU111970 - Expected Behavior Violation CVE-2025-4435 |
CWE-440 | Low | 3.6.8-47.el8_6.8, 3.6.8-51.el8_8.10, 3.6.8-70.el8_10 | 26.06.2025 |
SB2025062630 SB2025062633 SB2025062634 and 59 more |
||
| #VU111969 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-12718 |
CWE-22 | Medium | 3.6.8-47.el8_6.8, 3.6.8-51.el8_8.10, 3.6.8-70.el8_10 | 26.06.2025 |
SB2025062630 SB2025062633 SB2025062634 and 62 more |
||
| #VU111968 - Improper Link Resolution Before File Access ('Link Following') CVE-2025-4138 |
CWE-59 | High | 3.6.8-47.el8_6.8, 3.6.8-51.el8_8.10, 3.6.8-70.el8_10 | 26.06.2025 |
SB2025062630 SB2025062633 SB2025062634 and 64 more |
||
| #VU111967 - Improper Link Resolution Before File Access ('Link Following') CVE-2025-4330 |
CWE-59 | High | 3.6.8-47.el8_6.8, 3.6.8-51.el8_8.10, 3.6.8-70.el8_10 | 26.06.2025 |
SB2025062630 SB2025062633 SB2025062634 and 63 more |
||
| #VU111966 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-4517 |
CWE-22 | High | 3.6.8-47.el8_6.8, 3.6.8-51.el8_8.10, 3.6.8-70.el8_10 | 26.06.2025 |
SB2025062630 SB2025062633 SB2025062634 and 77 more |
||
| #VU103812 - Improper input validation CVE-2025-0938 |
CWE-20 | Low | 3.6.8-74.el8_10 | 11.02.2025 |
SB20250211115 SB20250211130 SB20250211131 and 77 more |
||
| #VU100516 - Improper input validation CVE-2024-11168 |
CWE-20 | Medium | 3.6.8-69.el8_10 | 15.11.2024 |
SB2024111507 SB2024111526 SB2024111527 and 76 more |
||
| #VU99357 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2024-9287 |
CWE-78 | Low | 3.6.8-69.el8_10 | 28.10.2024 |
SB2024102836 SB2024102838 SB20241101111 and 117 more |
||
| #VU96745 - Incorrect Regular Expression CVE-2024-6232 |
CWE-185 | Medium | 3.6.8-10.el7_7.1, 3.6.8-21.el7_9.1, 3.6.8-67.el8_10 | 03.09.2024 |
SB2024090377 SB2024090927 SB2024091048 and 145 more |
||
| #VU95571 - Command injection CVE-2024-6923 |
CWE-77 | Medium | 3.6.8-67.el8_10 | 08.08.2024 |
SB2024080861 SB2024080862 SB2024080863 and 144 more |
||
| #VU95157 - Incorrect Provision of Specified Functionality CVE-2024-4032 |
CWE-684 | Medium | 3.6.8-47.el8_6.7, 3.6.8-67.el8_10 | 02.08.2024 |
SB2024080203 SB2024080207 SB2024080209 and 101 more |
||
| #VU87685 - Resource exhaustion CVE-2024-0450 |
CWE-400 | Medium | 3.6.8-47.el8_6.6, 3.6.8-51.el8_8.6, 3.6.8-62.el8_10 | 21.03.2024 |
SB2024032107 SB2024032110 SB2024040848 and 80 more |
||
| #VU87185 - UNIX Symbolic Link (Symlink) Following CVE-2023-6597 |
CWE-61 | Low | 3.6.8-24.el8_2.3, 3.6.8-39.el8_4.5, 3.6.8-47.el8_6.6, 3.6.8-51.el8_8.6, 3.6.8-62.el8_10 | 07.03.2024 |
SB2024030718 SB2024030726 SB2024030727 and 88 more |
||
| #VU82077 - Resource exhaustion CVE-2022-48564 |
CWE-400 | Medium | 3.6.8-47.el8_6.4, 3.6.8-51.el8_8.4 | 17.10.2023 |
SB2023101707 SB20231123125 SB2023112746 and 19 more |
Showing elements 1 - 20 out of 44