Python
Curated coverage and analysis in this editorial area.

aeon: RCE via eval() in Python Dataset Loading, Patch Released
ZDI-26-469 discloses a code injection vulnerability in the Python aeon library. The use of eval() during dataset loading allows arbitr…

CVE-2026-6100: CPython Use-After-Free in Decompressors Rated CVSS 9.1 Critical
CVE-2026-6100 affects CPython with a use-after-free in the lzma, bz2, and gzip decompressors. The CVSS 4.0 score is 9.1 CRITICAL, thou…