Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Python" — 230 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
996
Esta semana
RSS
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92215] A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is …
A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the component FileResolver. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The identifier of the patch is 2bb8423060308bbdea8ba…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91943] Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStra…
Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs that redirect to internal addresses or use DNS rebinding to access internal services, exfiltrating responses through PDF text extraction in crawl results.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-91771] Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the Fi…
Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences to write files outside the intended download directory, potentially enabling code execution through modification of shell startup files or Python import p…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54447] garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages act…
garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. Prior to 0.3.5, garminconnect/client.py Client.dump creates the OAuth token directory and garmin_tokens.json without explicit owner-only modes, so a permissive umask such as 022 can leave the directory mode at 0755 and the token file mode at 0644. garmin_tokens.json contains di_refresh_toke…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90946] DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenti…
DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript, YAML, and JSON files containing hardcoded secrets and credentials.
M Alto vulnerabilidad
13/09/2026
[CVE-2026-37008] CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstrac…
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library without relying in any import statements. In other words, a within-process sandbox …
M Alto vulnerabilidad
13/09/2026
[CVE-2026-29811] CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the …
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81211] IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88029] Improper neutralization of special elements in data query logic in the GridFS component of the Mongo…
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected application may obtain stored file content beyond the intended target or ca…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87999] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search in backend/open_webui/retrieval/web/utils.py treated Python's globally routable address classification as proof that a destination was external. An authenticated user could make an Azure-hosted instance fetch and ret…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87996] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 unt…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Playwright browser resolve it again in the sync and async request interceptors. An authenticated user controlling authoritative DNS could return a public ad…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87874] A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although…
A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a n…
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad de denegación de servicio en GitPython anterior a 3.1.60
GitPython versions anteriores a 3.1.60 contienen una vulnerabilidad de expresión regular en Actor.name_email_regex que procesa campos de autor en commits. Un atacante puede inyectar commits con campos de autor malformados (corchetes angulares sin cerrar) para provocar retroceso cuadrático en el parsing, agotando recursos CPU durante más de 2 minutos por acceso a commit. Esto afecta principalmente a plataformas de CI/CD y servidores de repositorios en LATAM que procesan commits de fuentes externas.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad alta en GitPython anterior a 3.1.60 permite ejecución de código arbitrario
GitPython versiones anteriores a 3.1.60 no valida correctamente la ubicación del directorio git, permitiendo que atacantes suplanten directorios git mediante archivos rastreados (gitdir, commondir, HEAD) e inyecten hooks maliciosos de pre-commit. Al ejecutar index.commit() en repositorios clonados o abiertos, se dispara código arbitrario en el contexto del usuario afectado, comprometiendo servidores de CI/CD, máquinas de desarrolladores y sistemas de control de versiones en empresas LATAM.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en libxml2 con bindings Python permite denegación de servicio remota
Se ha identificado un fallo en libxml2 (cuando está compilado con bindings de Python) que permite a atacantes remotos provocar una denegación de servicio mediante documentos XML especialmente diseñados con Definiciones de Tipo de Documento (DTD) que contienen valores de atributos enumerados. La vulnerabilidad explota un error de doble liberación de memoria en el manejador de retrollamada SAX attributeDecl, afectando potencialmente servidores web, APIs y aplicaciones que procesan XML en entornos LATAM.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad alta de ejecución remota de código en Axolotl hasta versión 0.18.0
Axolotl versiones 0.18.0 y anteriores contienen una vulnerabilidad de ejecución remota de código (RCE) en la ruta de parche multipack. El parámetro trust_remote_code por defecto es None en lugar de False, permitiendo a atacantes eludir los controles de seguridad. Un adversario puede ejecutar código Python arbitrario al comprometer repositorios de modelos en Hugging Face utilizados como base_model, que se cargan con trust_remote_code=True forzado. Esto afecta principalmente a equipos de ML/IA en LATAM que utilizan modelos preentrenados de repositorios públicos sin validación.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85694] LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract…
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85525] Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a r…
Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle attacker holding a revoked certificate and its private key for a Snowflake or stage ho…
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad alta en HTTPX2: falla de inicio de TLS en conexiones WebSocket seguras por proxy SOCKS5
HTTPX2 (cliente HTTP de próxima generación para Python) versiones anteriores a 2.10.0 no inicia correctamente TLS al conectar a servidores WebSocket seguro (wss://) a través de proxy SOCKS5, debido a que el validador de protocolo solo reconoce https. La falla afecta aplicaciones que usan Client.websocket() y AsyncClient.websocket() desde v2.6.0, exponiendo comunicaciones que deberían estar cifradas en entornos corporativos y financieros de LATAM.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad de desbordamiento de memoria en HTTPX2 anterior a versión 2.12.0 (CVE-2026-84382)
HTTPX2, cliente HTTP de nueva generación para Python, contiene una vulnerabilidad en sus decodificadores de contenido (gzip, deflate, br, zstd) que permite ataques de denegación de servicio. Fragmentos comprimidos de 64 KiB pueden expandirse hasta 64 MiB en memoria, causando consumo excesivo de recursos en servidores y aplicaciones Python. Afecta principalmente a infraestructuras que procesan contenido comprimido desde orígenes no confiables.