Known vulnerabilities in python (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:python_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 16
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting python (Red Hat package) python (Red Hat package) is affected by 16 known vulnerabilities: 13 medium, 3 low Critical High Medium Low

Vulnerabilities (16)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU122819 - Command injection
CVE-2025-15367
CWE-77 Medium
No
No
2.6.6-70.el6_10.2, 2.7.5-94.el7_9.3 13.02.2026 SB2026021343
SB2026021347
SB2026021348
and 56 more
#VU122818 - Command injection
CVE-2025-15366
CWE-77 Medium
No
No
2.6.6-70.el6_10.2, 2.7.5-94.el7_9.3 13.02.2026 SB2026021343
SB2026021347
SB2026021348
and 52 more
#VU119238 - Inefficient Algorithmic Complexity
CVE-2025-12084
CWE-407 Low
No
No
2.7.5-94.el7_9.2 06.12.2025 SB2025120606
SB20251226352
SB2025123104
and 48 more
#VU80228 - Cleartext Transmission of Sensitive Information
CVE-2023-40217
CWE-319 Medium
No
No
2.6.6-70.el6_10, 2.7.5-94.el7_9 01.09.2023 SB2023090142
SB2023090143
SB2023090144
and 139 more
#VU72618 - Improper input validation
CVE-2023-24329
CWE-20 Medium
No
No
2.6.6-69.el6_10, 2.7.5-93.el7_9 28.02.2023 SB2023022819
SB2023022822
SB2023030832
and 158 more
#VU32881 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2019-20907
CWE-835 Medium
No
No
2.7.5-64.el7_4, 2.7.5-84.el7_6, 2.7.5-88.el7_7, 2.7.5-90.el7 29.07.2020 SB2020071324
SB2020080201
SB2020082408
and 53 more
#VU22617 - Improper input validation
CVE-2019-16056
CWE-20 Low
No
No
2.7.5-87.el7_7, 2.7.5-88.el7 10.11.2019 SB2019111003
SB2019111004
SB2019110649
and 31 more
#VU21440 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-16935
CWE-79 Medium
No
No
2.7.5-89.el7 30.09.2019 SB2019093008
SB2019111003
SB2019111004
and 24 more
#VU19256 - Exposure of sensitive information to an unauthorized actor
CVE-2018-20852
CWE-200 Medium
No
No
2.7.5-88.el7 19.07.2019 SB2019071301
SB2019082304
SB2019082305
and 16 more
#VU18829 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2019-9740
CWE-93 Medium
No
No
2.7.5-63.el7_4, 2.7.5-74.el7_5, 2.7.5-83.el7_6 19.06.2019 SB2019031318
SB2019062812
SB2019072603
and 32 more
#VU18828 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2019-9947
CWE-93 Medium
No
No
2.7.5-63.el7_4, 2.7.5-74.el7_5, 2.7.5-83.el7_6 19.06.2019 SB2019031318
SB2019062812
SB2019072603
and 22 more
#VU18827 - Exposed Dangerous Method or Function
CVE-2019-9948
CWE-749 Medium
No
No
2.7.5-63.el7_4, 2.7.5-74.el7_5, 2.7.5-83.el7_6 19.06.2019 SB2019031318
SB2019061903
SB2019042504
and 18 more
#VU15760 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2018-14647
CWE-611 Low
No
No
2.7.5-63.el7_4, 2.7.5-74.el7_5, 2.7.5-83.el7_6 08.11.2018 SB2018110808
SB2018122106
SB2018092802
and 35 more
#VU12283 - Improper input validation
CVE-2018-1060
CWE-20 Medium
No
No
2.7.5-63.el7_4, 2.7.5-74.el7_5 27.04.2018 SB2018042706
SB2018111109
SB2018120712
and 36 more
#VU12282 - Improper input validation
CVE-2018-1061
CWE-20 Medium
No
No
2.7.5-63.el7_4, 2.7.5-74.el7_5 27.04.2018 SB2018042706
SB2018111109
SB2018120712
and 20 more
#VU33825 - Improper input validation
CVE-2014-9365
CWE-20 Medium
No
No
2.7.5-58.el7 12.12.2014 SB2014121206
SB2015080503
SB2015031809
and 1 more