Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Python" — 286 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87999] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.1, POST /api/v1/retrieval/process/web and POST /api/v1/retrieval/process/web/search in backend/open_webui/retrieval/web/utils.py treated Python's globally routable address classification as proof that a destination was external. An authenticated user could make an Azure-hosted instance fetch and ret…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87996] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 unt…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Playwright browser resolve it again in the sync and async request interceptors. An authenticated user controlling authoritative DNS could return a public ad…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87874] A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although…
A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a n…
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad de denegación de servicio en GitPython anterior a 3.1.60
GitPython versions anteriores a 3.1.60 contienen una vulnerabilidad de expresión regular en Actor.name_email_regex que procesa campos de autor en commits. Un atacante puede inyectar commits con campos de autor malformados (corchetes angulares sin cerrar) para provocar retroceso cuadrático en el parsing, agotando recursos CPU durante más de 2 minutos por acceso a commit. Esto afecta principalmente a plataformas de CI/CD y servidores de repositorios en LATAM que procesan commits de fuentes externas.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad alta en GitPython anterior a 3.1.60 permite ejecución de código arbitrario
GitPython versiones anteriores a 3.1.60 no valida correctamente la ubicación del directorio git, permitiendo que atacantes suplanten directorios git mediante archivos rastreados (gitdir, commondir, HEAD) e inyecten hooks maliciosos de pre-commit. Al ejecutar index.commit() en repositorios clonados o abiertos, se dispara código arbitrario en el contexto del usuario afectado, comprometiendo servidores de CI/CD, máquinas de desarrolladores y sistemas de control de versiones en empresas LATAM.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en libxml2 con bindings Python permite denegación de servicio remota
Se ha identificado un fallo en libxml2 (cuando está compilado con bindings de Python) que permite a atacantes remotos provocar una denegación de servicio mediante documentos XML especialmente diseñados con Definiciones de Tipo de Documento (DTD) que contienen valores de atributos enumerados. La vulnerabilidad explota un error de doble liberación de memoria en el manejador de retrollamada SAX attributeDecl, afectando potencialmente servidores web, APIs y aplicaciones que procesan XML en entornos LATAM.
M Alto vulnerabilidad
05/09/2026
Vulnerabilidad alta de ejecución remota de código en Axolotl hasta versión 0.18.0
Axolotl versiones 0.18.0 y anteriores contienen una vulnerabilidad de ejecución remota de código (RCE) en la ruta de parche multipack. El parámetro trust_remote_code por defecto es None en lugar de False, permitiendo a atacantes eludir los controles de seguridad. Un adversario puede ejecutar código Python arbitrario al comprometer repositorios de modelos en Hugging Face utilizados como base_model, que se cargan con trust_remote_code=True forzado. Esto afecta principalmente a equipos de ML/IA en LATAM que utilizan modelos preentrenados de repositorios públicos sin validación.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85694] LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract…
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the operator's host without review.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85525] Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a r…
Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle attacker holding a revoked certificate and its private key for a Snowflake or stage ho…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85394] python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepti…
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an incomplete fix for CVE-2024-33663.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad alta en HTTPX2: falla de inicio de TLS en conexiones WebSocket seguras por proxy SOCKS5
HTTPX2 (cliente HTTP de próxima generación para Python) versiones anteriores a 2.10.0 no inicia correctamente TLS al conectar a servidores WebSocket seguro (wss://) a través de proxy SOCKS5, debido a que el validador de protocolo solo reconoce https. La falla afecta aplicaciones que usan Client.websocket() y AsyncClient.websocket() desde v2.6.0, exponiendo comunicaciones que deberían estar cifradas en entornos corporativos y financieros de LATAM.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad de desbordamiento de memoria en HTTPX2 anterior a versión 2.12.0 (CVE-2026-84382)
HTTPX2, cliente HTTP de nueva generación para Python, contiene una vulnerabilidad en sus decodificadores de contenido (gzip, deflate, br, zstd) que permite ataques de denegación de servicio. Fragmentos comprimidos de 64 KiB pueden expandirse hasta 64 MiB en memoria, causando consumo excesivo de recursos en servidores y aplicaciones Python. Afecta principalmente a infraestructuras que procesan contenido comprimido desde orígenes no confiables.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84366] Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/co…
Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta["is_secure"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A n…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-83551] Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in …
Cleartext storage of sensitive information in the @step and @remote decorator pipeline component in Amazon SageMaker Python SDK before v3.11.0 and v2.256.0 might allow an authenticated remote user to extract the HMAC signing key from SageMaker DescribePipeline API responses and forge valid integrity signatures for specially crafted function payloads, achieving code execution in another user's pipe…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84202] ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary c…
ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82397] Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parse…
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestHandler._execute in tornado/web.py parses the body before handler dispatch through HTTPServerRequest._parse_body and parse_body_arguments in tornado/httputil.py, …
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82278] BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoin…
BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v1/workflow/run_once endpoint, which executes them with exec() without sandboxing, gaining access to filesystem, credentials, and internal network resources.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55485] Piccolo Admin is an admin interface and content management system for Python, built on top of Piccol…
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables, while piccolo_api/session_auth/tables.py exposes SessionsBase.token because the token column is no…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-10036] SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to…
SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_possible(). Attackers can embed malicious Python object construction tags such as !!python/object/apply in any CKPT.yaml file w…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81690] openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 ad…
openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in CPython does not descend into symlinked directories and treats the symlink as an ordinary directory, while O_NOFOLLOW on the hash side binds only the final path component. An evil-maid attacker with physical access to the …