cbcvebase.
CVE-2026-3298
published 2026-04-21

CVE-2026-3298: The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter…

PriorityP352high8.8CVSS 4.0
AVNACLATNPRNUINVCLVILVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.37%
30.0th percentile
The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected.

Affected

3 ranges
VendorProductVersion rangeFixed in
python_software_foundationcpython>= 3.11.0 < 3.13.143.13.14
python_software_foundationcpython>= 3.14.0a1 < 3.14.5rc13.14.5rc1
python_software_foundationcpython>= 3.15.0a1 < 3.15.0b13.15.0b1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.