Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Python" — 230 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84366] Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/co…
Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta["is_secure"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A n…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-83551] Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in …
Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipe…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84202] ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary c…
ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82397] Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parse…
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestHandler._execute in tornado/web.py parses the body before handler dispatch through HTTPServerRequest._parse_body and parse_body_arguments in tornado/httputil.py, …
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82278] BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoin…
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow/run_once endpoint, which executes them with exec() without sandboxing, gaining access to filesystem, credentials, and internal network resources.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55485] Piccolo Admin is an admin interface and content management system for Python, built on top of Piccol…
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables, while piccolo_api/session_auth/tables.py exposes SessionsBase.token because the token column is no…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-10036] SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to…
SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_possible(). Attackers can embed malicious Python object construction tags such as !!python/object/apply in any CKPT.yaml file w…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81690] openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 ad…
openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not descend into symlinked directories and treats the symlink as an ordinary directory, while O_NOFOLLOW on the hash side binds only the final path component. An evil-maid attacker with physical access to the …
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80205] NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.fin…
NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers can supply crafted regex patterns that cause catastrophic backtracking, resulting in indefinite CPU saturation and denial of service to all users of the Python process.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-57170] Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance doc…
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown file as Jinja2 template code in a non-sandboxed environment, allowing server-side template injection that can lead to arbitr…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-57171] Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance doc…
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an attacker-influenced output path without path-traversal validation, allowing arbitrary file write outside the Trestle workspace. …
M Alto vulnerabilidad
25/08/2026
Inyección de plantillas en Compliance-trestle permite ejecución remota de código
Compliance-trestle (versiones anteriores a 3.12.4 y 4.0.0-4.0.3) contiene una vulnerabilidad de inyección de plantillas del lado del servidor en las etiquetas Jinja2 MDCleanInclude y MDSectionInclude. Un atacante puede ejecutar código arbitrario reparseando contenido Markdown no confiable como código fuente de plantilla. Afecta a organizaciones que utilizan Trestle para gestionar documentos de cumplimiento OSCAL en México y LATAM.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55099] icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 u…
icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membership test invokes the same method on child components, causing O(2^n) work relative to nesting depth. Component.from_ical accepts arbitrarily nested BEG…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-45019] Chainlit is a Python framework for building production-ready conversational AI applications. From 2.…
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For sse and streamable-http transports, ConnectSseMCPRequest and ConnectStreamableHttpMCPRequest in backend/chainlit/types.py accep…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78379] Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Ag…
Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute arbitrary Python code on the agent's host by bypassing the human consent gate, via a crafted prompt that forwards non_interactive_mode as a keyword argument through the batch tool. To remediate this issue, users should upgrade to version 0…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55620] eml_parser serves as a python module for parsing eml files and returning various information found i…
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.2, eml_parser.routing.noparenthesis in eml_parser/routing.py removes parenthesized CFWS comments from Received: headers with a regex-based fix-point loop whose running time is quadratic in the nesting depth. A single Received: header with 5,…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55585] QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, to…
QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() without restricted global_dict and local_dict namespaces, allowing Python eval() to resolve builtins and execute arbitrary P…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78677] GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers t…
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook executio…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78675] GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers…
GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target fi…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-76098] Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vul…
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can exceed Python's recursion limit and raise RecursionError, allowing crafted Markdown to crash a parsing pr…