Python Software Foundation

Security Scorecard

Score

90B

Total CVEs

18

Patch Rate

83%

15 patched

Avg Response

-

days to patch

Critical Gaps

0

exploitable, no detection

Severity Breakdown

Critical1
High9
Medium7
Low0

Patch Status

Patched15 (83%)
Partial/Workaround0 (0%)
Unpatched3 (17%)

CVEs (19)

CVE IDTitleSeverityScoreDaysPatch
CVE-2026-24123BentoML Path Traversal VulnerabilityHigh7.4-Patched
CVE-2026-24049Wheel Unpacking VulnerabilityHigh7.1-Patched
CVE-2026-22702CVE-2026-22702Medium4.5-Patched
CVE-2026-21441CVE-2026-21441High7.5-Patched
CVE-2025-66471urllib3 HTTP Client Library Compression BugHigh7.5-Patched
CVE-2025-13837Plistlib Module OOM and DoS VulnerabilityMedium5.5-Patched
CVE-2025-13836HTTP Client Buffer Overflow VulnerabilityCritical9.1-Patched
CVE-2025-12638-High8.015dUnpatched
CVE-2025-61911-Medium6.5-Patched
CVE-2025-61912-Medium5.3-Patched