CVE-2026-0864
published 2026-06-23CVE-2026-0864: When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file…
PriorityP417medium4.1CVSS 4.0
AVLACLATPPRHUIPVCNVIHVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.13%
2.8th percentile
When using the "configparser" module to write configuration files
containing multi-line text values with carriage return characters (\r) the
resulting file could be injected with unexpected keys and values if the
attacker controls the written value.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| python36_3.6 | python36 | — | — |
| python_software_foundation | cpython | < 3.15.0 | 3.15.0 |
CVSS provenance
nvdv4.04.1MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat4.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python: cpython: Python configparser: Configuration injection via crafted multi-line input
vendor_redhat·2026-06-23·CVSS 4.1
CVE-2026-0864 [MEDIUM] CWE-93 python: cpython: Python configparser: Configuration injection via crafted multi-line input
python: cpython: Python configparser: Configuration injection via crafted multi-line input
When using the "configparser" module to write configuration files
containing multi-line text values with carriage return characters (\r) the
resulting file could be injected with unexpected keys and values if the
attacker controls the written value.
A flaw was found in the Python `configparser` module. When writing configuration files, an attacker who controls the input value can inject unexpected keys and values. This occurs if the input contains multi-line text with carriage return characters, leading to potential configuration manipulation.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprisin
VulDB
Python CPython up to 3.14.x Configuration injection (ID 143927)
vuldb·2026-06-23·CVSS 4.1
CVE-2026-0864 [MEDIUM] Python CPython up to 3.14.x Configuration injection (ID 143927)
A vulnerability labeled as critical has been found in Python CPython up to 3.14.x. This affects an unknown part of the component Configuration Handler. Executing a manipulation can lead to injection.
This vulnerability is tracked as CVE-2026-0864. The attack is restricted to local execution. No exploit exists.
The affected component should be upgraded.
GHSA
When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and v
ghsa_unreviewed·2026-06-23
CVE-2026-0864 [MEDIUM] CWE-74 When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and v
When using the "configparser" module to write configuration files
containing multi-line text values with carriage return characters (\r) the
resulting file could be injected with unexpected keys and values if the
attacker controls the written value.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-0864 python: cpython: Python configparser: Configuration injection via crafted multi-line input
bugzilla·2026-06-23·CVSS 4.1
CVE-2026-0864 [MEDIUM] CVE-2026-0864 python: cpython: Python configparser: Configuration injection via crafted multi-line input
CVE-2026-0864 python: cpython: Python configparser: Configuration injection via crafted multi-line input
When using the "configparser" module to write configuration files
containing multi-line text values with carriage return characters (\r) the
resulting file could be injected with unexpected keys and values if the
attacker controls the written value.
Bugzilla
CVE-2026-0864 mercurial: Python configparser: Configuration injection via crafted multi-line input [fedora-all]
bugzilla·2026-06-23·CVSS 4.1
CVE-2026-0864 [MEDIUM] CVE-2026-0864 mercurial: Python configparser: Configuration injection via crafted multi-line input [fedora-all]
CVE-2026-0864 mercurial: Python configparser: Configuration injection via crafted multi-line input [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-0864 mercurial: Python configparser: Configuration injection via crafted multi-line input [epel-all]
bugzilla·2026-06-23·CVSS 4.1
CVE-2026-0864 [MEDIUM] CVE-2026-0864 mercurial: Python configparser: Configuration injection via crafted multi-line input [epel-all]
CVE-2026-0864 mercurial: Python configparser: Configuration injection via crafted multi-line input [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851fhttps://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8https://github.com/python/cpython/issues/143927https://github.com/python/cpython/pull/151559https://mail.python.org/archives/list/[email protected]/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/
2026-06-23
Published