Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-0864

Опубликовано: 23 июн. 2026
Источник: debian
EPSS Низкий

Описание

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14fixed3.14.7-1package
python3.13fixed3.13.15-1package
python3.13no-dsatrixiepackage
python3.11removedpackage
python3.11postponedbookwormpackage
python3.9removedpackage
python3.9postponedbullseyepackage
python2.7removedpackage
python2.7end-of-lifebullseyepackage
pypy3unfixedpackage
pypy3no-dsatrixiepackage
pypy3postponedbookwormpackage
pypy3postponedbullseyepackage

Примечания

  • https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/

  • https://github.com/python/cpython/issues/143927

  • https://github.com/python/cpython/pull/152003 (3.14)

  • https://github.com/python/cpython/pull/152004 (3.13)

  • https://github.com/python/cpython/pull/152006 (3.11)

  • https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f (main)

  • https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98 (v3.14.7)

  • https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8 (v3.13.15)

EPSS

Процентиль: 4%
0.00139
Низкий

Связанные уязвимости

ubuntu
около 2 месяцев назад

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

CVSS3: 5.5
redhat
около 2 месяцев назад

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

nvd
около 2 месяцев назад

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

msrc
около 1 месяца назад

Configuration Injection via Carriage Return (\r) in write() method

github
около 2 месяцев назад

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

EPSS

Процентиль: 4%
0.00139
Низкий