Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4519

Опубликовано: 20 мар. 2026
Источник: redhat
CVSS3: 7.1

Описание

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

A flaw was found in Python. The webbrowser.open() API, used to launch web browsers, does not properly sanitize input. This allows a remote attacker to craft a malicious URL containing leading dashes. When such a URL is opened, certain web browsers may interpret these dashes as command-line options, which could lead to unexpected behavior, information disclosure, or potentially arbitrary code execution, impacting the integrity of the system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat Enterprise Linux 8python39-devel:3.9/python39Not affected
Red Hat Enterprise Linux 10python3.12FixedRHSA-2026:625631.03.2026
Red Hat Enterprise Linux 10python3.14FixedRHSA-2026:1901919.05.2026
Red Hat Enterprise Linux 10python3.12FixedRHSA-2026:1906419.05.2026
Red Hat Enterprise Linux 10.0 Extended Update Supportpython3.12FixedRHSA-2026:724409.04.2026
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONpythonFixedRHSA-2026:1010223.04.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportpythonFixedRHSA-2026:961422.04.2026
Red Hat Enterprise Linux 7 Extended Lifecycle Supportpython3FixedRHSA-2026:974522.04.2026
Red Hat Enterprise Linux 8python3.11FixedRHSA-2026:628131.03.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2449649python: Python: Command-line option injection in webbrowser.open() via crafted URLs

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
4 месяца назад

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

CVSS3: 3.3
nvd
4 месяца назад

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

msrc
4 месяца назад

webbrowser.open() allows leading dashes in URLs

CVSS3: 3.3
debian
4 месяца назад

The webbrowser.open() API would accept leading dashes in the URL which ...

rocky
4 месяца назад

Important: python3.9 security update

7.1 High

CVSS3