boks Index
Docs Releases

python

1 tool · 6 release lines

CPython interpreter + standard library. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing python from python@latest → 3.14.7 stable python@3.10 → 3.10.21 stable python@3.11 → 3.11.16 stable python@3.12 → 3.12.14 stable python@3.13 → 3.13.15 stable python@3.14 → 3.14.7 stable

Findings

H4M27

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-41080 ↗ H 7.5 expat libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVE-2026-45186 ↗ H 7.5 expat In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
CVE-2026-54876 ↗ H 7.5 openssl Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.
CVE-2026-56132 ↗ M 6.9 expat In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVE-2026-56403 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-56404 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56405 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56406 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
CVE-2026-56407 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-56408 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-56410 ↗ M 6.9 expat xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56411 ↗ M 6.9 expat xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56409 ↗ M 6.5 expat xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-72522 ↗ M 6.2 expat libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
CVE-2025-15367 ↗ M 5.9 python The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2026-50219 ↗ M 5.9 expat libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
CVE-2026-56412 ↗ M 5.9 expat libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur.
CVE-2025-66382 ↗ M 5.5 expat In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
CVE-2026-32776 ↗ M 5.5 expat libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
CVE-2026-32777 ↗ M 5.5 expat libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
CVE-2026-32778 ↗ M 5.5 expat libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
CVE-2026-13595 ↗ M 5.3 util-linux A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array.
CVE-2026-3184 ↗ M 5.3 util-linux A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`.
CVE-2026-4360 ↗ M 5.3 python In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the…
CVE-2026-56131 ↗ M 4.9 expat libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
CVE-2026-27456 ↗ M 4.7 util-linux util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux.
CVE-2026-53612 ↗ M util-linux CVE-2026-53612
CVE-2026-53613 ↗ M util-linux CVE-2026-53613
CVE-2026-53614 ↗ M util-linux CVE-2026-53614
CVE-2026-53615 ↗ M util-linux CVE-2026-53615

3 further advisories matched this image and were assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex
CVE-2026-42250 bzip2 not affected · vex
CVE-2026-4739 expat not affected · vex

These are the findings of python, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Findings

H9M33L2?1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-3298 ↗ H 8.8 python The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter.
CVE-2023-36632 ↗ H 7.5 python The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling a Python object" via a crafted argument.
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-3644 ↗ H 7.5 python The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation.
CVE-2026-41080 ↗ H 7.5 expat libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVE-2026-4224 ↗ H 7.5 python When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.
CVE-2026-45186 ↗ H 7.5 expat In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
CVE-2026-54876 ↗ H 7.5 openssl Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.
CVE-2026-7210 ↗ H 7.5 python `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating…
CVE-2026-56132 ↗ M 6.9 expat In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVE-2026-56403 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-56404 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56405 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56406 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
CVE-2026-56407 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-56408 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-56410 ↗ M 6.9 expat xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56411 ↗ M 6.9 expat xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56409 ↗ M 6.5 expat xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-72522 ↗ M 6.2 expat libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
CVE-2026-6019 ↗ M 6.1 python http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element.
CVE-2026-3446 ↗ M 6.0 python When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed.
CVE-2025-15366 ↗ M 5.9 python The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2025-15367 ↗ M 5.9 python The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2026-50219 ↗ M 5.9 expat libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
CVE-2026-56412 ↗ M 5.9 expat libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur.
CVE-2025-13837 ↗ M 5.5 python When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
CVE-2025-66382 ↗ M 5.5 expat In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
CVE-2026-32776 ↗ M 5.5 expat libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
CVE-2026-32777 ↗ M 5.5 expat libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
CVE-2026-32778 ↗ M 5.5 expat libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
CVE-2025-12781 ↗ M 5.3 python When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish…
CVE-2026-12003 ↗ M 5.3 python To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local.
CVE-2026-13595 ↗ M 5.3 util-linux A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array.
CVE-2026-3184 ↗ M 5.3 util-linux A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`.
CVE-2026-4360 ↗ M 5.3 python In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the…
CVE-2026-56131 ↗ M 4.9 expat libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
CVE-2026-27456 ↗ M 4.7 util-linux util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux.
CVE-2025-13462 ↗ L 3.3 python The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK.
CVE-2026-4519 ↗ L 3.3 python The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes.
CVE-2026-53612 ↗ M util-linux CVE-2026-53612
CVE-2026-53613 ↗ M util-linux CVE-2026-53613
CVE-2026-53614 ↗ M util-linux CVE-2026-53614
CVE-2026-53615 ↗ M util-linux CVE-2026-53615
CVE-2026-3479 ↗ ? 0.0 python DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point.

3 further advisories matched this image and were assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex
CVE-2026-42250 bzip2 not affected · vex
CVE-2026-4739 expat not affected · vex

These are the findings of python, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Findings

H7M32L2?1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-3644 ↗ H 7.5 python The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation.
CVE-2026-41080 ↗ H 7.5 expat libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVE-2026-4224 ↗ H 7.5 python When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.
CVE-2026-45186 ↗ H 7.5 expat In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
CVE-2026-54876 ↗ H 7.5 openssl Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.
CVE-2026-7210 ↗ H 7.5 python `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating…
CVE-2026-56132 ↗ M 6.9 expat In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVE-2026-56403 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-56404 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56405 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56406 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
CVE-2026-56407 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-56408 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-56410 ↗ M 6.9 expat xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56411 ↗ M 6.9 expat xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56409 ↗ M 6.5 expat xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-72522 ↗ M 6.2 expat libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
CVE-2026-6019 ↗ M 6.1 python http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element.
CVE-2026-3446 ↗ M 6.0 python When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed.
CVE-2025-15366 ↗ M 5.9 python The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2025-15367 ↗ M 5.9 python The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2026-50219 ↗ M 5.9 expat libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
CVE-2026-56412 ↗ M 5.9 expat libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur.
CVE-2025-13837 ↗ M 5.5 python When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
CVE-2025-66382 ↗ M 5.5 expat In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
CVE-2026-32776 ↗ M 5.5 expat libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
CVE-2026-32777 ↗ M 5.5 expat libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
CVE-2026-32778 ↗ M 5.5 expat libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
CVE-2025-12781 ↗ M 5.3 python When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish…
CVE-2026-13595 ↗ M 5.3 util-linux A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array.
CVE-2026-3184 ↗ M 5.3 util-linux A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`.
CVE-2026-4360 ↗ M 5.3 python In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the…
CVE-2026-56131 ↗ M 4.9 expat libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
CVE-2026-27456 ↗ M 4.7 util-linux util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux.
CVE-2025-13462 ↗ L 3.3 python The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK.
CVE-2026-4519 ↗ L 3.3 python The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes.
CVE-2026-53612 ↗ M util-linux CVE-2026-53612
CVE-2026-53613 ↗ M util-linux CVE-2026-53613
CVE-2026-53614 ↗ M util-linux CVE-2026-53614
CVE-2026-53615 ↗ M util-linux CVE-2026-53615
CVE-2026-3479 ↗ ? 0.0 python DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point.

3 further advisories matched this image and were assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex
CVE-2026-42250 bzip2 not affected · vex
CVE-2026-4739 expat not affected · vex

These are the findings of python, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Findings

H7M32L2?1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-3644 ↗ H 7.5 python The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation.
CVE-2026-41080 ↗ H 7.5 expat libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVE-2026-4224 ↗ H 7.5 python When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow occurs.
CVE-2026-45186 ↗ H 7.5 expat In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
CVE-2026-54876 ↗ H 7.5 openssl Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.
CVE-2026-7210 ↗ H 7.5 python `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating…
CVE-2026-56132 ↗ M 6.9 expat In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVE-2026-56403 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-56404 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56405 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56406 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
CVE-2026-56407 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-56408 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-56410 ↗ M 6.9 expat xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56411 ↗ M 6.9 expat xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56409 ↗ M 6.5 expat xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-72522 ↗ M 6.2 expat libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
CVE-2026-6019 ↗ M 6.1 python http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element.
CVE-2026-3446 ↗ M 6.0 python When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed.
CVE-2025-15366 ↗ M 5.9 python The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2025-15367 ↗ M 5.9 python The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2026-50219 ↗ M 5.9 expat libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
CVE-2026-56412 ↗ M 5.9 expat libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur.
CVE-2025-13837 ↗ M 5.5 python When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues
CVE-2025-66382 ↗ M 5.5 expat In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
CVE-2026-32776 ↗ M 5.5 expat libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
CVE-2026-32777 ↗ M 5.5 expat libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
CVE-2026-32778 ↗ M 5.5 expat libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
CVE-2025-12781 ↗ M 5.3 python When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish…
CVE-2026-13595 ↗ M 5.3 util-linux A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array.
CVE-2026-3184 ↗ M 5.3 util-linux A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`.
CVE-2026-4360 ↗ M 5.3 python In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the…
CVE-2026-56131 ↗ M 4.9 expat libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
CVE-2026-27456 ↗ M 4.7 util-linux util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux.
CVE-2025-13462 ↗ L 3.3 python The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK.
CVE-2026-4519 ↗ L 3.3 python The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes.
CVE-2026-53612 ↗ M util-linux CVE-2026-53612
CVE-2026-53613 ↗ M util-linux CVE-2026-53613
CVE-2026-53614 ↗ M util-linux CVE-2026-53614
CVE-2026-53615 ↗ M util-linux CVE-2026-53615
CVE-2026-3479 ↗ ? 0.0 python DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point.

3 further advisories matched this image and were assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex
CVE-2026-42250 bzip2 not affected · vex
CVE-2026-4739 expat not affected · vex

These are the findings of python, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Findings

H4M27

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-41080 ↗ H 7.5 expat libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVE-2026-45186 ↗ H 7.5 expat In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
CVE-2026-54876 ↗ H 7.5 openssl Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.
CVE-2026-56132 ↗ M 6.9 expat In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVE-2026-56403 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-56404 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56405 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56406 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
CVE-2026-56407 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-56408 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-56410 ↗ M 6.9 expat xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56411 ↗ M 6.9 expat xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56409 ↗ M 6.5 expat xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-72522 ↗ M 6.2 expat libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
CVE-2025-15367 ↗ M 5.9 python The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2026-50219 ↗ M 5.9 expat libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
CVE-2026-56412 ↗ M 5.9 expat libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur.
CVE-2025-66382 ↗ M 5.5 expat In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
CVE-2026-32776 ↗ M 5.5 expat libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
CVE-2026-32777 ↗ M 5.5 expat libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
CVE-2026-32778 ↗ M 5.5 expat libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
CVE-2026-13595 ↗ M 5.3 util-linux A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array.
CVE-2026-3184 ↗ M 5.3 util-linux A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`.
CVE-2026-4360 ↗ M 5.3 python In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the…
CVE-2026-56131 ↗ M 4.9 expat libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
CVE-2026-27456 ↗ M 4.7 util-linux util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux.
CVE-2026-53612 ↗ M util-linux CVE-2026-53612
CVE-2026-53613 ↗ M util-linux CVE-2026-53613
CVE-2026-53614 ↗ M util-linux CVE-2026-53614
CVE-2026-53615 ↗ M util-linux CVE-2026-53615

3 further advisories matched this image and were assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex
CVE-2026-42250 bzip2 not affected · vex
CVE-2026-4739 expat not affected · vex

These are the findings of python, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Findings

H4M27

identical on arm64, amd64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-41080 ↗ H 7.5 expat libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.
CVE-2026-45186 ↗ H 7.5 expat In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
CVE-2026-54876 ↗ H 7.5 openssl Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries.
CVE-2026-56132 ↗ M 6.9 expat In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVE-2026-56403 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-56404 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-56405 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-56406 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
CVE-2026-56407 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-56408 ↗ M 6.9 expat libexpat before 2.8.2 has an integer overflow in copyString.
CVE-2026-56410 ↗ M 6.9 expat xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-56411 ↗ M 6.9 expat xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-56409 ↗ M 6.5 expat xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-72522 ↗ M 6.2 expat libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.
CVE-2025-15367 ↗ M 5.9 python The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
CVE-2026-50219 ↗ M 5.9 expat libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
CVE-2026-56412 ↗ M 5.9 expat libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur.
CVE-2025-66382 ↗ M 5.5 expat In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
CVE-2026-32776 ↗ M 5.5 expat libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
CVE-2026-32777 ↗ M 5.5 expat libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
CVE-2026-32778 ↗ M 5.5 expat libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.
CVE-2026-13595 ↗ M 5.3 util-linux A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array.
CVE-2026-3184 ↗ M 5.3 util-linux A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`.
CVE-2026-4360 ↗ M 5.3 python In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the…
CVE-2026-56131 ↗ M 4.9 expat libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
CVE-2026-27456 ↗ M 4.7 util-linux util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux.
CVE-2026-53612 ↗ M util-linux CVE-2026-53612
CVE-2026-53613 ↗ M util-linux CVE-2026-53613
CVE-2026-53614 ↗ M util-linux CVE-2026-53614
CVE-2026-53615 ↗ M util-linux CVE-2026-53615

3 further advisories matched this image and were assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex
CVE-2026-42250 bzip2 not affected · vex
CVE-2026-4739 expat not affected · vex

These are the findings of python, which ships every tool in this project. boks reports and gates; it never edits an image to clear a finding.

Composition

default + env
runtime none — self-contained
composes env

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. boks resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/boks-sh/python:3.14.7
digest
platforms
size 39 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/boks-sh/python:3.10.21
digest
platforms
size 36 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/boks-sh/python:3.11.16
digest
platforms
size 38 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/boks-sh/python:3.12.14
digest
platforms
size 39 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/boks-sh/python:3.13.15
digest
platforms
size 38 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/boks-sh/python:3.14.7
digest
platforms
size 39 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

python

capabilities

rw

Filled is granted by default; the rest need --cap at the point of use.

seccomp tier

per tool

spawn, net-listen

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

none

env passed through

0 of 1

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, boks scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

31 findings across this project at latest, 45 at 3.10 . Counted once per advisory across every image the project builds.