{"grype_matches":[{"artifact":{"id":"3dc7b39bbf35e882","cpes":["cpe:2.3:a:python-software-foundation:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-software-foundation:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-software-foundation:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-3.14:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-3.14:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_3.14:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_3.14:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-3.14:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_3.14:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*"],"name":"python-3.14","purl":"pkg:apk/wolfi/python-3.14@3.14.8_git20261008-r1?arch=x86_64&distro=wolfi-20230201","type":"apk","version":"3.14.8_git20261008-r1","language":"","licenses":["PSF-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/pydoc3"},{"path":"/usr/bin/python"},{"path":"/usr/bin/python3"},{"path":"/usr/lib"},{"path":"/usr/lib/python3.14"},{"path":"/var"},{"path":"/var/lib"},{"path":"/var/lib/db"},{"path":"/var/lib/db/sbom"},{"path":"/var/lib/db/sbom/python-3.14-3.14.8_git20261008-r1.spdx.json"}]},"locations":[{"path":"/usr/lib/apk/db/installed","layerID":"sha256:1d128d17bfb1e779ab1fd9e4ab48eafe83113fc61f86e10bda9ed492a8cc0cca","accessPath":"/usr/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-3.14"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15367","versionConstraint":"< 3.15.0a6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.14.8_git20261008:*:*:*:*:*:*:*"],"package":{"name":"python-3.14","version":"3.14.8_git20261008-r1"},"namespace":"nvd:cpe"}},{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2025-15367","versionConstraint":"< 3.15.0a6 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.14.8_git20261008:*:*:*:*:*:*:*"],"package":{"name":"python-3.14","version":"3.14.8_git20261008-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2025-15367","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2025-15367","cwe":"CWE-77","type":"Secondary","source":"cna@python.org"}],"epss":[{"cve":"CVE-2025-15367","date":"2026-10-08","epss":0.00369,"percentile":0.28652}],"risk":0.20110500000000003,"urls":["https://github.com/python/cpython/commit/b234a2b67539f787e191d2ef19a7cbdce32874e7","https://github.com/python/cpython/issues/143923","https://github.com/python/cpython/pull/143924","https://mail.python.org/archives/list/security-announce@python.org/thread/CBFBOWVGGUJFSGITQCCBZS4GEYYZ7ZNE/"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2025-15367","description":"The poplib module, when passed a user-controlled command, can have\nadditional commands injected using newlines. Mitigation rejects commands\ncontaining control characters."},"relatedVulnerabilities":[]},{"artifact":{"id":"3dc7b39bbf35e882","cpes":["cpe:2.3:a:python-software-foundation:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-software-foundation:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-software-foundation:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_software_foundation:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-3.14:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-3.14:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_3.14:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_3.14:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-software:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_software:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python-3.14:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python:python-3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python:python_3.14:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python_3.14:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*","cpe:2.3:a:python:python:3.14.8_git20261008-r1:*:*:*:*:*:*:*"],"name":"python-3.14","purl":"pkg:apk/wolfi/python-3.14@3.14.8_git20261008-r1?arch=x86_64&distro=wolfi-20230201","type":"apk","version":"3.14.8_git20261008-r1","language":"","licenses":["PSF-2.0"],"metadata":{"Arch":"x86_64","files":[{"path":"/usr"},{"path":"/usr/bin"},{"path":"/usr/bin/pydoc3"},{"path":"/usr/bin/python"},{"path":"/usr/bin/python3"},{"path":"/usr/lib"},{"path":"/usr/lib/python3.14"},{"path":"/var"},{"path":"/var/lib"},{"path":"/var/lib/db"},{"path":"/var/lib/db/sbom"},{"path":"/var/lib/db/sbom/python-3.14-3.14.8_git20261008-r1.spdx.json"}]},"locations":[{"path":"/usr/lib/apk/db/installed","layerID":"sha256:1d128d17bfb1e779ab1fd9e4ab48eafe83113fc61f86e10bda9ed492a8cc0cca","accessPath":"/usr/lib/apk/db/installed","annotations":{"evidence":"primary"}}],"upstreams":[{"name":"python-3.14"}],"metadataType":"ApkMetadata"},"matchDetails":[{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-12345","versionConstraint":"< 3.15.0rc3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python:python:3.14.8_git20261008:*:*:*:*:*:*:*"],"package":{"name":"python-3.14","version":"3.14.8_git20261008-r1"},"namespace":"nvd:cpe"}},{"type":"cpe-match","found":{"cpes":["cpe:2.3:a:python_software_foundation:python:*:*:*:*:*:*:*:*"],"vulnerabilityID":"CVE-2026-12345","versionConstraint":"< 3.15.0rc3 (unknown)"},"matcher":"apk-matcher","searchedBy":{"cpes":["cpe:2.3:a:python_software_foundation:python:3.14.8_git20261008:*:*:*:*:*:*:*"],"package":{"name":"python-3.14","version":"3.14.8_git20261008-r1"},"namespace":"nvd:cpe"}}],"vulnerability":{"id":"CVE-2026-12345","fix":{"state":"unknown","versions":[]},"cvss":[{"type":"Secondary","source":"cna@python.org","vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","metrics":{"baseScore":5.9},"version":"4.0","vendorMetadata":{}}],"cwes":[{"cve":"CVE-2026-12345","cwe":"CWE-59","type":"Secondary","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"epss":[{"cve":"CVE-2026-12345","date":"2026-10-08","epss":0.0018,"percentile":0.06911}],"risk":0.0981,"urls":["https://github.com/python/cpython/commit/06ef3d43fdaf4da97af12fa694b4886092c4b970","https://github.com/python/cpython/commit/458e7134a5af7f86aee9d21b51cf499b41aa4420","https://github.com/python/cpython/commit/5c20517a4fc56683efe63a7751020db9573f538d","https://github.com/python/cpython/commit/e1f3590f155c6d66007e958c98c9d69316551993","https://github.com/python/cpython/issues/157579","https://github.com/python/cpython/pull/157580","http://www.openwall.com/lists/oss-security/2026/09/29/40"],"severity":"Medium","namespace":"nvd:cpe","advisories":[],"dataSource":"https://nvd.nist.gov/vuln/detail/CVE-2026-12345","description":"The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms."},"relatedVulnerabilities":[]}],"grade":"A","score":"100.00","as_of":"2026-10-10T02:42:38.706Z","grype_db_version":"2026-10-09T06:32:32.000Z"}