Описание
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| python3.14 | fixed | 3.14.5-1 | package | |
| python3.13 | fixed | 3.13.14-1 | package | |
| python3.13 | not-affected | trixie | package | |
| python3.11 | not-affected | package | ||
| python3.9 | not-affected | package | ||
| python2.7 | not-affected | package | ||
| jython | not-affected | package | ||
| pypy3 | fixed | 7.3.22+dfsg-1 | package | |
| pypy3 | not-affected | trixie | package | |
| pypy3 | not-affected | bookworm | package | |
| pypy3 | not-affected | bullseye | package |
Примечания
Incomplete fix for CVE-2026-4519, followup fixes listed there:
https://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/
https://github.com/python/cpython/issues/148169
https://github.com/python/cpython/pull/148170
https://github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53 (v3.14.5rc1)
EPSS
Связанные уязвимости
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
EPSS