restrictedpython vulnerabilities
CVEs whose affected-version data names the restrictedpython package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-76825High· 8.4RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment
RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed…
▾ Twilightzopefoundation · RestrictedPythonEPSS 0.57%via NVD
CVE-2026-55830High· 8.3RestrictedPython guard hooks can be shadowed via positional-only arguments
RestrictedPython guard hooks can be shadowed via positional-only arguments
▾ Twilightrestrictedpython · restrictedpythonEPSS 0.23%via OSV
CVE-2025-22153High· 7.9try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter
try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter
▾ Twilightrestrictedpython · restrictedpythonEPSS 0.40%via OSV
CVE-2023-37271High· 8.4RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape
RestrictedPython vulnerable to arbitrary code execution via stack frame sandbox escape
▾ Twilightrestrictedpython · restrictedpythonEPSS 0.85%via OSV