{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: xml.etree.ElementTree Element.findall(), iterfind()\n     and find() were vulnerable to a quadratic-complexity CPU denial of\n     service.  Evaluating an XPath index predicate ([1], [last()],\n     [last()-N]) against a document with many same-tag siblings re-ran\n     parent.findall(elem.tag) once per candidate element, which is\n     quadratic in the number of siblings.\n     - debian/patches/CVE-2026-6879.patch: backport of cpython\n       2ffab083 (gh-152674).  Caches the element selected by the index\n       predicate per (parent, tag) pair, so each sibling group is\n       scanned only once.\n     - CVE-2026-6879",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809",
        "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_python/ubuntu16.04/advisories/2026/clsa-2026_1787735809.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-26T16:31:33Z",
      "generator": {
        "date": "2026-08-26T16:31:33Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1787735809",
      "initial_release_date": "2026-08-26T09:18:39Z",
      "revision_history": [
        {
          "date": "2026-08-26T09:18:39Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-26T16:31:33Z",
          "number": "2",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Fix CVE(s): CVE-2007-4559, CVE-2025-4517, CVE-2026-6100"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 16.04",
                "product": {
                  "name": "Ubuntu 16.04",
                  "product_id": "Ubuntu-16",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-python37-test-0:3.7.17-30.amd64",
                "product": {
                  "name": "alt-python37-test-0:3.7.17-30.amd64",
                  "product_id": "alt-python37-test-0:3.7.17-30.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python37-test@3.7.17-30?arch=amd64&os_name=ubuntu&os_version=16.04"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python37-0:3.7.17-30.amd64",
                "product": {
                  "name": "alt-python37-0:3.7.17-30.amd64",
                  "product_id": "alt-python37-0:3.7.17-30.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python37@3.7.17-30?arch=amd64&os_name=ubuntu&os_version=16.04"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python37-libs-0:3.7.17-30.amd64",
                "product": {
                  "name": "alt-python37-libs-0:3.7.17-30.amd64",
                  "product_id": "alt-python37-libs-0:3.7.17-30.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python37-libs@3.7.17-30?arch=amd64&os_name=ubuntu&os_version=16.04"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python37-debug-0:3.7.17-30.amd64",
                "product": {
                  "name": "alt-python37-debug-0:3.7.17-30.amd64",
                  "product_id": "alt-python37-debug-0:3.7.17-30.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python37-debug@3.7.17-30?arch=amd64&os_name=ubuntu&os_version=16.04"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python37-tkinter-0:3.7.17-30.amd64",
                "product": {
                  "name": "alt-python37-tkinter-0:3.7.17-30.amd64",
                  "product_id": "alt-python37-tkinter-0:3.7.17-30.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python37-tkinter@3.7.17-30?arch=amd64&os_name=ubuntu&os_version=16.04"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python37-tools-0:3.7.17-30.amd64",
                "product": {
                  "name": "alt-python37-tools-0:3.7.17-30.amd64",
                  "product_id": "alt-python37-tools-0:3.7.17-30.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python37-tools@3.7.17-30?arch=amd64&os_name=ubuntu&os_version=16.04"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-python37-devel-0:3.7.17-30.amd64",
                "product": {
                  "name": "alt-python37-devel-0:3.7.17-30.amd64",
                  "product_id": "alt-python37-devel-0:3.7.17-30.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-python37-devel@3.7.17-30?arch=amd64&os_name=ubuntu&os_version=16.04"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python37-test-0:3.7.17-30.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64"
        },
        "product_reference": "alt-python37-test-0:3.7.17-30.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python37-0:3.7.17-30.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:alt-python37-0:3.7.17-30.amd64"
        },
        "product_reference": "alt-python37-0:3.7.17-30.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python37-libs-0:3.7.17-30.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64"
        },
        "product_reference": "alt-python37-libs-0:3.7.17-30.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python37-debug-0:3.7.17-30.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64"
        },
        "product_reference": "alt-python37-debug-0:3.7.17-30.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python37-tkinter-0:3.7.17-30.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64"
        },
        "product_reference": "alt-python37-tkinter-0:3.7.17-30.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python37-tools-0:3.7.17-30.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
        },
        "product_reference": "alt-python37-tools-0:3.7.17-30.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-python37-devel-0:3.7.17-30.amd64 as a component of Ubuntu 16.04",
          "product_id": "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64"
        },
        "product_reference": "alt-python37-devel-0:3.7.17-30.amd64",
        "relates_to_product_reference": "Ubuntu-16"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2022-48565",
      "cwe": {
        "id": "CWE-611",
        "name": "Improper Restriction of XML External Entity Reference"
      },
      "notes": [
        {
          "category": "description",
          "text": "An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-48565"
        },
        {
          "category": "external",
          "summary": "https://bugs.python.org/issue42051",
          "url": "https://bugs.python.org/issue42051"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00022.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00017.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AFHYAGWBFBNUGWU6XWKBHTCV5NH77MB7/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAYWJD576JUKLHCWKDLMJSUGTRDKPF3M/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KZRZRJHWLZ7MOJNPQBWGJVXMVYDC5BRA/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20231006-0007/",
          "url": "https://security.netapp.com/advisory/ntap-20231006-0007/"
        }
      ],
      "release_date": "2023-08-22T19:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-26T09:17:10.795536Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809",
          "product_ids": [
            "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-6100",
      "cwe": {
        "id": "CWE-416",
        "name": "Use After Free"
      },
      "notes": [
        {
          "category": "description",
          "text": "Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in this specific error condition.\n\nThe vulnerability is only present if the program re-uses decompressor instances across multiple decompression calls even after a `MemoryError` is raised during decompression. Using the helper functions to one-shot decompress data such as `lzma.decompress()`, `bz2.decompress()`, `gzip.decompress()`, and `zlib.decompress()` are not affected as a new decompressor instance is used per call. If the decompressor instance is not re-used after an error condition, this usage is similarly not vulnerable.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2026-6100"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/47128e64f98c3a20271138a98c2922bea2a3ee0e",
          "url": "https://github.com/python/cpython/commit/47128e64f98c3a20271138a98c2922bea2a3ee0e"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d",
          "url": "https://github.com/python/cpython/commit/6a5f79c8d7bbf22b083b240910c7a8781a59437d"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2",
          "url": "https://github.com/python/cpython/commit/8fc66aef6d7b3ae58f43f5c66f9366cc8cbbfcd2"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20",
          "url": "https://github.com/python/cpython/commit/c3cf71c3366fe49acb776a639405c0eea6169c20"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/e20c6c9667c99ecaab96e1a2b3767082841ffc8b",
          "url": "https://github.com/python/cpython/commit/e20c6c9667c99ecaab96e1a2b3767082841ffc8b"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/ea8d735eb084cf8cc021df1a30e90d10a8f052e3",
          "url": "https://github.com/python/cpython/commit/ea8d735eb084cf8cc021df1a30e90d10a8f052e3"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/issues/148395",
          "url": "https://github.com/python/cpython/issues/148395"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/148396",
          "url": "https://github.com/python/cpython/pull/148396"
        },
        {
          "category": "external",
          "summary": "https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/",
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/HTWB2Z6KT5QQX4RYEZAFININDHNOSIF3/"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/04/13/10",
          "url": "http://www.openwall.com/lists/oss-security/2026/04/13/10"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10117",
          "url": "https://access.redhat.com/errata/RHSA-2026:10117"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10140",
          "url": "https://access.redhat.com/errata/RHSA-2026:10140"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10141",
          "url": "https://access.redhat.com/errata/RHSA-2026:10141"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10711",
          "url": "https://access.redhat.com/errata/RHSA-2026:10711"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10745",
          "url": "https://access.redhat.com/errata/RHSA-2026:10745"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10774",
          "url": "https://access.redhat.com/errata/RHSA-2026:10774"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10949",
          "url": "https://access.redhat.com/errata/RHSA-2026:10949"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:10950",
          "url": "https://access.redhat.com/errata/RHSA-2026:10950"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:11062",
          "url": "https://access.redhat.com/errata/RHSA-2026:11062"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:11077",
          "url": "https://access.redhat.com/errata/RHSA-2026:11077"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:11768",
          "url": "https://access.redhat.com/errata/RHSA-2026:11768"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13692",
          "url": "https://access.redhat.com/errata/RHSA-2026:13692"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:13812",
          "url": "https://access.redhat.com/errata/RHSA-2026:13812"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14652",
          "url": "https://access.redhat.com/errata/RHSA-2026:14652"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14653",
          "url": "https://access.redhat.com/errata/RHSA-2026:14653"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:14656",
          "url": "https://access.redhat.com/errata/RHSA-2026:14656"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:16699",
          "url": "https://access.redhat.com/errata/RHSA-2026:16699"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:17525",
          "url": "https://access.redhat.com/errata/RHSA-2026:17525"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:17619",
          "url": "https://access.redhat.com/errata/RHSA-2026:17619"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19019",
          "url": "https://access.redhat.com/errata/RHSA-2026:19019"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19064",
          "url": "https://access.redhat.com/errata/RHSA-2026:19064"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19175",
          "url": "https://access.redhat.com/errata/RHSA-2026:19175"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19176",
          "url": "https://access.redhat.com/errata/RHSA-2026:19176"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19177",
          "url": "https://access.redhat.com/errata/RHSA-2026:19177"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19216",
          "url": "https://access.redhat.com/errata/RHSA-2026:19216"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19549",
          "url": "https://access.redhat.com/errata/RHSA-2026:19549"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19570",
          "url": "https://access.redhat.com/errata/RHSA-2026:19570"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19571",
          "url": "https://access.redhat.com/errata/RHSA-2026:19571"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19576",
          "url": "https://access.redhat.com/errata/RHSA-2026:19576"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:19590",
          "url": "https://access.redhat.com/errata/RHSA-2026:19590"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:21275",
          "url": "https://access.redhat.com/errata/RHSA-2026:21275"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:21682",
          "url": "https://access.redhat.com/errata/RHSA-2026:21682"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:25096",
          "url": "https://access.redhat.com/errata/RHSA-2026:25096"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:26187",
          "url": "https://access.redhat.com/errata/RHSA-2026:26187"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30078",
          "url": "https://access.redhat.com/errata/RHSA-2026:30078"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30087",
          "url": "https://access.redhat.com/errata/RHSA-2026:30087"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30088",
          "url": "https://access.redhat.com/errata/RHSA-2026:30088"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30089",
          "url": "https://access.redhat.com/errata/RHSA-2026:30089"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:52400",
          "url": "https://access.redhat.com/errata/RHSA-2026:52400"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8822",
          "url": "https://access.redhat.com/errata/RHSA-2026:8822"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:8824",
          "url": "https://access.redhat.com/errata/RHSA-2026:8824"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:9228",
          "url": "https://access.redhat.com/errata/RHSA-2026:9228"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-6100",
          "url": "https://access.redhat.com/security/cve/CVE-2026-6100"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2457932"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6100.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6100.json"
        }
      ],
      "release_date": "2026-04-13T18:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-26T09:17:10.795536Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809",
          "product_ids": [
            "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2022-37454",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "notes": [
        {
          "category": "description",
          "text": "The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2022-37454"
        },
        {
          "category": "external",
          "summary": "https://csrc.nist.gov/projects/hash-functions/sha-3-project",
          "url": "https://csrc.nist.gov/projects/hash-functions/sha-3-project"
        },
        {
          "category": "external",
          "summary": "https://eprint.iacr.org/2023/331",
          "url": "https://eprint.iacr.org/2023/331"
        },
        {
          "category": "external",
          "summary": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658",
          "url": "https://github.com/XKCP/XKCP/security/advisories/GHSA-6w4m-2xhg-2658"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html",
          "url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00041.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html",
          "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00000.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3ALQ6BDDPX5HU5YBQOBMDVAA2TSGDKIJ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMIEXLMTW5GO36HTFFWIPB3OHZXCT3G4/"
        },
        {
          "category": "external",
          "summary": "https://mouha.be/sha-3-buffer-overflow/",
          "url": "https://mouha.be/sha-3-buffer-overflow/"
        },
        {
          "category": "external",
          "summary": "https://news.ycombinator.com/item?id=33281106",
          "url": "https://news.ycombinator.com/item?id=33281106"
        },
        {
          "category": "external",
          "summary": "https://news.ycombinator.com/item?id=35050307",
          "url": "https://news.ycombinator.com/item?id=35050307"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202305-02",
          "url": "https://security.gentoo.org/glsa/202305-02"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2022/dsa-5267",
          "url": "https://www.debian.org/security/2022/dsa-5267"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2022/dsa-5269",
          "url": "https://www.debian.org/security/2022/dsa-5269"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20230203-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20230203-0001/"
        }
      ],
      "release_date": "2022-10-21T06:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-26T09:17:10.795536Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809",
          "product_ids": [
            "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2020-27619",
      "notes": [
        {
          "category": "description",
          "text": "In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2020-27619"
        },
        {
          "category": "external",
          "summary": "https://bugs.python.org/issue41944",
          "url": "https://bugs.python.org/issue41944"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3cab8",
          "url": "https://github.com/python/cpython/commit/2ef5caa58febc8968e670e39e3d37cf8eef3cab8"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd2a9",
          "url": "https://github.com/python/cpython/commit/43e523103886af66d6c27cd72431b5d9d14cd2a9"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3ac33",
          "url": "https://github.com/python/cpython/commit/6c6c256df3636ff6f6136820afaefa5a10a3ac33"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794",
          "url": "https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/e912e945f2960029d039d3390ea08835ad39374b",
          "url": "https://github.com/python/cpython/commit/e912e945f2960029d039d3390ea08835ad39374b"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E",
          "url": "https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E",
          "url": "https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E",
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RSLQD5CCM75IZGAMBDGUZEATYU5YSGJ7/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGIY6I4YS3WOXAK4SXKIEOC2G4VZKIR7/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202402-04",
          "url": "https://security.gentoo.org/glsa/202402-04"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20201123-0004/",
          "url": "https://security.netapp.com/advisory/ntap-20201123-0004/"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpujul2022.html",
          "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
        }
      ],
      "release_date": "2020-10-22T03:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-26T09:17:10.795536Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809",
          "product_ids": [
            "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2019-9948",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "notes": [
        {
          "category": "description",
          "text": "urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2019-9948"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html"
        },
        {
          "category": "external",
          "summary": "http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.html",
          "url": "http://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.html"
        },
        {
          "category": "external",
          "summary": "http://www.securityfocus.com/bid/107549",
          "url": "http://www.securityfocus.com/bid/107549"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:1700",
          "url": "https://access.redhat.com/errata/RHSA-2019:1700"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:2030",
          "url": "https://access.redhat.com/errata/RHSA-2019:2030"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:3335",
          "url": "https://access.redhat.com/errata/RHSA-2019:3335"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:3520",
          "url": "https://access.redhat.com/errata/RHSA-2019:3520"
        },
        {
          "category": "external",
          "summary": "https://bugs.python.org/issue35907",
          "url": "https://bugs.python.org/issue35907"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/11842",
          "url": "https://github.com/python/cpython/pull/11842"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E",
          "url": "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html",
          "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2019/07/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2019/07/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html",
          "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/"
        },
        {
          "category": "external",
          "summary": "https://seclists.org/bugtraq/2019/Oct/29",
          "url": "https://seclists.org/bugtraq/2019/Oct/29"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202003-26",
          "url": "https://security.gentoo.org/glsa/202003-26"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20190404-0004/",
          "url": "https://security.netapp.com/advisory/ntap-20190404-0004/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4127-1/",
          "url": "https://usn.ubuntu.com/4127-1/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4127-2/",
          "url": "https://usn.ubuntu.com/4127-2/"
        }
      ],
      "release_date": "2019-03-23T18:29:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-26T09:17:10.795536Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809",
          "product_ids": [
            "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2007-4559",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2007-4559"
        },
        {
          "category": "external",
          "summary": "http://mail.python.org/pipermail/python-dev/2007-August/074290.html",
          "url": "http://mail.python.org/pipermail/python-dev/2007-August/074290.html"
        },
        {
          "category": "external",
          "summary": "http://mail.python.org/pipermail/python-dev/2007-August/074292.html",
          "url": "http://mail.python.org/pipermail/python-dev/2007-August/074292.html"
        },
        {
          "category": "external",
          "summary": "http://secunia.com/advisories/26623",
          "url": "http://secunia.com/advisories/26623"
        },
        {
          "category": "external",
          "summary": "http://www.vupen.com/english/advisories/2007/3022",
          "url": "http://www.vupen.com/english/advisories/2007/3022"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=263261",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=263261"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202309-06",
          "url": "https://security.gentoo.org/glsa/202309-06"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVBB7NU3YIRRDOKLYVN647WPRR3IAKR6/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FI55PGL47ES3OU2FQPGEHOI2EK3S2OBH/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KA4Z44ZAI4SY7THCFBUDNT5EEFO4XQ3A/"
        }
      ],
      "release_date": "2007-08-28T01:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-26T09:17:10.795536Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809",
          "product_ids": [
            "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2019-9636",
      "notes": [
        {
          "category": "description",
          "text": "Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2019-9636"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00097.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00097.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00024.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00024.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html"
        },
        {
          "category": "external",
          "summary": "http://www.securityfocus.com/bid/107400",
          "url": "http://www.securityfocus.com/bid/107400"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHBA-2019:0763",
          "url": "https://access.redhat.com/errata/RHBA-2019:0763"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHBA-2019:0764",
          "url": "https://access.redhat.com/errata/RHBA-2019:0764"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHBA-2019:0959",
          "url": "https://access.redhat.com/errata/RHBA-2019:0959"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:0710",
          "url": "https://access.redhat.com/errata/RHSA-2019:0710"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:0765",
          "url": "https://access.redhat.com/errata/RHSA-2019:0765"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:0806",
          "url": "https://access.redhat.com/errata/RHSA-2019:0806"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:0902",
          "url": "https://access.redhat.com/errata/RHSA-2019:0902"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:0981",
          "url": "https://access.redhat.com/errata/RHSA-2019:0981"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:0997",
          "url": "https://access.redhat.com/errata/RHSA-2019:0997"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:1467",
          "url": "https://access.redhat.com/errata/RHSA-2019:1467"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:2980",
          "url": "https://access.redhat.com/errata/RHSA-2019:2980"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:3170",
          "url": "https://access.redhat.com/errata/RHSA-2019:3170"
        },
        {
          "category": "external",
          "summary": "https://bugs.python.org/issue36216",
          "url": "https://bugs.python.org/issue36216"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/12201",
          "url": "https://github.com/python/cpython/pull/12201"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html",
          "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html",
          "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html",
          "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46PVWY5LFP4BRPG3BVQ5QEEFYBVEXHCK/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46PVWY5LFP4BRPG3BVQ5QEEFYBVEXHCK/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AEZ5IQT7OF7Q2NCGIVABOWYGKO7YU3NJ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AEZ5IQT7OF7Q2NCGIVABOWYGKO7YU3NJ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CFBAAGM27H73OLYBUA2IAZFSUN6KGLME/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CFBAAGM27H73OLYBUA2IAZFSUN6KGLME/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D3LXPABKVLFYUHRYJPM3CSS5MS6FXKS7/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D3LXPABKVLFYUHRYJPM3CSS5MS6FXKS7/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICBEGRHIPHWPG2VGYS6R4EVKVUUF4AQW/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ICBEGRHIPHWPG2VGYS6R4EVKVUUF4AQW/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFAXBEY2TGOBDRKTR556JBXBVFSAKD6I/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IFAXBEY2TGOBDRKTR556JBXBVFSAKD6I/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMWSKTNOHSUOT3L25QFJAVCFYZX46FYK/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JSKPGPZQNTAULHW4UH63KGOOUIDE4RRB/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JSKPGPZQNTAULHW4UH63KGOOUIDE4RRB/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXASHCDD4PQFKTMKQN4YOP5ZH366ABN4/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L25RTMKCF62DLC2XVSNXGX7C7HXISLVM/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L25RTMKCF62DLC2XVSNXGX7C7HXISLVM/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TR6GCO3WTV4D5L23WTCBF275VE6BVNI3/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TR6GCO3WTV4D5L23WTCBF275VE6BVNI3/"
        },
        {
          "category": "external",
          "summary": "https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization.html",
          "url": "https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization.html"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202003-26",
          "url": "https://security.gentoo.org/glsa/202003-26"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20190517-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20190517-0001/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4127-1/",
          "url": "https://usn.ubuntu.com/4127-1/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4127-2/",
          "url": "https://usn.ubuntu.com/4127-2/"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpujan2020.html",
          "url": "https://www.oracle.com/security-alerts/cpujan2020.html"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpujul2022.html",
          "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
        }
      ],
      "release_date": "2019-03-08T21:29:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-26T09:17:10.795536Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809",
          "product_ids": [
            "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2019-10160",
      "cwe": {
        "id": "CWE-172",
        "name": "Encoding Error"
      },
      "notes": [
        {
          "category": "description",
          "text": "A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2019-10160"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00042.html"
        },
        {
          "category": "external",
          "summary": "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html",
          "url": "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:1587",
          "url": "https://access.redhat.com/errata/RHSA-2019:1587"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:1700",
          "url": "https://access.redhat.com/errata/RHSA-2019:1700"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2019:2437",
          "url": "https://access.redhat.com/errata/RHSA-2019:2437"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10160",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10160"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e09",
          "url": "https://github.com/python/cpython/commit/250b62acc59921d399f0db47db3b462cd6037e09"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87e",
          "url": "https://github.com/python/cpython/commit/8d0ef0b5edeae52960c7ed05ae8a12388324f87e"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de",
          "url": "https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468",
          "url": "https://github.com/python/cpython/commit/fd1771dbdd28709716bd531580c40ae5ed814468"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E",
          "url": "https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html",
          "url": "https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html",
          "url": "https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html",
          "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00034.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ORNTF62QPLMJXIQ7KTZQ2776LMIXEKL/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/44TS66GJMO5H3RLMVZEBGEFTB6O2LJJU/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4X3HW5JRZ7GCPSR7UHJOLD7AWLTQCDVR/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E2HP37NUVLQSBW3J735A2DQDOZ4ZGBLY/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ER6LONC2B2WYIO56GBQUDU6QTWZDPUNQ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCPGLTTOBB3QEARDX4JOYURP6ELNNA2V/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M34WOYCDKTDE5KLUACE2YIEH7D37KHRX/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NF3DRDGMVIRYNZMSLJIHNW47HOUQYXVG/"
        },
        {
          "category": "external",
          "summary": "https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization2.html",
          "url": "https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization2.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20190617-0003/",
          "url": "https://security.netapp.com/advisory/ntap-20190617-0003/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4127-1/",
          "url": "https://usn.ubuntu.com/4127-1/"
        },
        {
          "category": "external",
          "summary": "https://usn.ubuntu.com/4127-2/",
          "url": "https://usn.ubuntu.com/4127-2/"
        }
      ],
      "release_date": "2019-06-07T18:29:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-26T09:17:10.795536Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809",
          "product_ids": [
            "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2025-4517",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Allows arbitrary filesystem writes outside the extraction directory during extraction with filter=\"data\".\n\n\nYou are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() or TarFile.extract() using the filter= parameter with a value of \"data\" or \"tar\". See the tarfile  extraction filters documentation https://docs.python.org/3/library/tarfile.html#tarfile-extraction-filter  for more information.\n\nNote that for Python 3.14 or later the default value of filter= changed from \"no filtering\" to `\"data\", so if you are relying on this new default behavior then your usage is also affected.\n\nNote that none of these vulnerabilities significantly affect the installation of source distributions which are tar archives as source distributions already allow arbitrary code execution during the build process. However when evaluating source distributions it's important to avoid installing source distributions with suspicious links.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2025-4517"
        },
        {
          "category": "external",
          "summary": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f",
          "url": "https://gist.github.com/sethmlarson/52398e33eff261329a0180ac1d54f42f"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da",
          "url": "https://github.com/python/cpython/commit/19de092debb3d7e832e5672cc2f7b788d35951da"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9",
          "url": "https://github.com/python/cpython/commit/28463dba112af719df1e8b0391c46787ad756dd9"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a",
          "url": "https://github.com/python/cpython/commit/3612d8f51741b11f36f8fb0494d79086bac9390a"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e",
          "url": "https://github.com/python/cpython/commit/4633f3f497b1ff70e4a35b6fe2c907cbe2d4cb2e"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a",
          "url": "https://github.com/python/cpython/commit/9c1110ef6652687d7c55f590f909720eddde965a"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a",
          "url": "https://github.com/python/cpython/commit/9e0ac76d96cf80b49055f6d6b9a6763fb9215c2a"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01",
          "url": "https://github.com/python/cpython/commit/aa9eb5f757ceff461e6e996f12c89e5d9b583b01"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1",
          "url": "https://github.com/python/cpython/commit/dd8f187d0746da151e0025c51680979ac5b4cfb1"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/issues/135034",
          "url": "https://github.com/python/cpython/issues/135034"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/135037",
          "url": "https://github.com/python/cpython/pull/135037"
        },
        {
          "category": "external",
          "summary": "https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/",
          "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/"
        }
      ],
      "release_date": "2025-06-03T13:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-26T09:17:10.795536Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809",
          "product_ids": [
            "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2021-3177",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
          "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-python/cve/CVE-2021-3177"
        },
        {
          "category": "external",
          "summary": "https://bugs.python.org/issue42938",
          "url": "https://bugs.python.org/issue42938"
        },
        {
          "category": "external",
          "summary": "https://github.com/python/cpython/pull/24239",
          "url": "https://github.com/python/cpython/pull/24239"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E",
          "url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html",
          "url": "https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html",
          "url": "https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/"
        },
        {
          "category": "external",
          "summary": "https://news.ycombinator.com/item?id=26185005",
          "url": "https://news.ycombinator.com/item?id=26185005"
        },
        {
          "category": "external",
          "summary": "https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html",
          "url": "https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202101-18",
          "url": "https://security.gentoo.org/glsa/202101-18"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20210226-0003/",
          "url": "https://security.netapp.com/advisory/ntap-20210226-0003/"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com//security-alerts/cpujul2021.html",
          "url": "https://www.oracle.com//security-alerts/cpujul2021.html"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpujan2022.html",
          "url": "https://www.oracle.com/security-alerts/cpujan2022.html"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpujul2022.html",
          "url": "https://www.oracle.com/security-alerts/cpujul2022.html"
        },
        {
          "category": "external",
          "summary": "https://www.oracle.com/security-alerts/cpuoct2021.html",
          "url": "https://www.oracle.com/security-alerts/cpuoct2021.html"
        }
      ],
      "release_date": "2021-01-19T06:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-08-26T09:17:10.795536Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809",
          "product_ids": [
            "Ubuntu-16:alt-python37-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-debug-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-devel-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-libs-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-test-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tkinter-0:3.7.17-30.amd64",
            "Ubuntu-16:alt-python37-tools-0:3.7.17-30.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-python/releases/CLSA-2026:1787735809"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    }
  ]
}