Python's CVE reports surge as ecosystem matures

CPython's security disclosures are accelerating sharply. Genuine vulnerability discovery and maturing disclosure incentives—bug bounty programs, coordinated CVE releases, researcher attention—have formalized what was once ad-hoc patching. This creates a credibility tension for the Python Foundation: more transparency signals due diligence, but higher CVE counts risk spooking enterprises that equate disclosure volume with insecurity, even as absolute risk per deployment may remain flat or improve.