Описание
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
A flaw was found in the Python webbrowser.open() API. If a specially crafted URL containing "%action" is processed, an attacker could bypass a previous mitigation for CVE-2026-4519. This bypass allows for command injection into the underlying shell, potentially leading to arbitrary code execution.
Отчет
This flaw in the Python webbrowser.open() API allows for command injection and arbitrary code execution when processing specially crafted URLs containing "%action". This bypasses a previous mitigation for CVE-2026-4519.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 7 | python3 | Affected | ||
| Red Hat Enterprise Linux 8 | python2 | Not affected | ||
| Red Hat Enterprise Linux 8 | python36 | Not affected | ||
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Not affected | ||
| Red Hat Enterprise Linux 8 | python38 | Will not fix | ||
| Red Hat Enterprise Linux 8 | python39 | Will not fix | ||
| Red Hat Enterprise Linux 10 | python3.12 | Fixed | RHSA-2026:10711 | 27.04.2026 |
| Red Hat Enterprise Linux 10 | python3.14 | Fixed | RHSA-2026:19019 | 19.05.2026 |
| Red Hat Enterprise Linux 10 | python3.12 | Fixed | RHSA-2026:19064 | 19.05.2026 |
| Red Hat Enterprise Linux 10 | python3.14 | Fixed | RHSA-2026:28581 | 24.06.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()
Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ...
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
EPSS
7.1 High
CVSS3