CVE-2026-3479
published 2026-03-18CVE-2026-3479: DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation…
PriorityP415low6.3CVSS 4.0
AVPACLATNPRNUINVCNVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.24%
14.8th percentile
DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.
pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pypy3 | — | — |
| debian | python2.7 | — | — |
| debian | python3.11 | — | — |
| debian | python3.13 | — | — |
| debian | python3.14 | — | — |
| debian | python3.9 | — | — |
| msrc | azl3_python3_3.12.9-9_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-11_on_azure_linux_3.0 | — | — |
| msrc | cbl2_python3_3.9.19-19_on_cbl_mariner_2.0 | — | — |
| python_software_foundation | cpython | < 3.13.13 | 3.13.13 |
| python_software_foundation | cpython | >= 3.14.0 < 3.14.4 | 3.14.4 |
| python_software_foundation | cpython | >= 3.15.0a1 < 3.15.0a8 | 3.15.0a8 |
CVSS provenance
nvdv4.00.0NONECVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat3.3NONE
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python: Python pkgutil.get_data(): Path Traversal via improper resource argument validation
vendor_redhat·2026-03-18·CVSS 3.3
CVE-2026-3479 [NONE] CWE-22 python: Python pkgutil.get_data(): Path Traversal via improper resource argument validation
python: Python pkgutil.get_data(): Path Traversal via improper resource argument validation
DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.
pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
A flaw was found in Python's `pkgutil.get_data()` function, which is used to retrieve data from packages. This function did not properly validate the `resource` argument, allowing a local attacker to perform path traversal attacks. Path traversal enables an attacker to access files and directories stored outside the intend
Microsoft
pkgutil.get_data() does not enforce documented restrictions
vendor_msrc·2026-03-10
CVE-2026-3479 [NONE] pkgutil.get_data() does not enforce documented restrictions
pkgutil.get_data() does not enforce documented restrictions
Mariner: Mariner
PSF: PSF
Customer Action Required: Yes
Debian
CVE-2026-3479: pypy3 - DISPUTED: The project has clarified that the documentation was incorrect, and th...
vendor_debian·2026
CVE-2026-3479 [NONE] CVE-2026-3479: pypy3 - DISPUTED: The project has clarified that the documentation was incorrect, and th...
DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
CVE-2026-3479: DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil
osv·2026-03-18
CVE-2026-3479 [NONE] CVE-2026-3479: DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil
DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model. pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
GHSA
GHSA-43rw-359f-4h89: pkgutil
ghsa_unreviewed·2026-03-18
CVE-2026-3479 [LOW] CWE-22 GHSA-43rw-359f-4h89: pkgutil
pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
OSV
CVE-2026-3479: pkgutil
osv·2026-03-18
CVE-2026-3479 [NONE] CVE-2026-3479: pkgutil
pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-3479 python3.14: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
bugzilla·2026-03-19
CVE-2026-3479 [NONE] CVE-2026-3479 python3.14: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
CVE-2026-3479 python3.14: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-884eccdb03 (python3.14-3.14.4-1.fc44 and python3-docs-3.14.4-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-884eccdb03
---
FEDORA-2026-9a8fddee0b (python3.14-3.14.4-1.fc43 and python3-docs-3.14.4-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-9a8fddee0b
Bugzilla
CVE-2026-3479 python3.10: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
bugzilla·2026-03-19
CVE-2026-3479 [NONE] CVE-2026-3479 python3.10: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
CVE-2026-3479 python3.10: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This CVE has been disputed: https://www.cve.org/CVERecord?id=CVE-2026-3479
Closing.
Bugzilla
CVE-2026-3479 python3.13: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
bugzilla·2026-03-19
CVE-2026-3479 [NONE] CVE-2026-3479 python3.13: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
CVE-2026-3479 python3.13: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-80165205dc (python3.13-3.13.13-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-80165205dc
---
FEDORA-2026-13c6899032 (python3.13-3.13.13-1.fc42 and python3-docs-3.13.13-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-13c6899032
Bugzilla
CVE-2026-3479 asahi-installer: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
bugzilla·2026-03-19
CVE-2026-3479 [NONE] CVE-2026-3479 asahi-installer: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
CVE-2026-3479 asahi-installer: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This CVE has been disputed: https://www.cve.org/CVERecord?id=CVE-2026-3479
Closing.
Bugzilla
CVE-2026-3479 mingw-python3: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
bugzilla·2026-03-19
CVE-2026-3479 [NONE] CVE-2026-3479 mingw-python3: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
CVE-2026-3479 mingw-python3: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-e20864d099 (mingw-python3-3.11.15-3.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-e20864d099
---
FEDORA-2026-6ef614f23c (mingw-python3-3.11.15-3.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-6ef614f23c
---
FEDORA-2026-e20864d099 has been pushed to the Fedora 43 testing repository.
Soon you'll be able t
Bugzilla
CVE-2026-3479 python3.6: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
bugzilla·2026-03-19
CVE-2026-3479 [NONE] CVE-2026-3479 python3.6: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
CVE-2026-3479 python3.6: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This CVE has been disputed: https://www.cve.org/CVERecord?id=CVE-2026-3479
Closing.
Bugzilla
CVE-2026-3479 python3.12: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
bugzilla·2026-03-19
CVE-2026-3479 [NONE] CVE-2026-3479 python3.12: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
CVE-2026-3479 python3.12: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This CVE has been disputed: https://www.cve.org/CVERecord?id=CVE-2026-3479
Closing.
Bugzilla
CVE-2026-3479 python3.13: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [epel-all]
bugzilla·2026-03-19
CVE-2026-3479 [NONE] CVE-2026-3479 python3.13: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [epel-all]
CVE-2026-3479 python3.13: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This CVE has been disputed: https://www.cve.org/CVERecord?id=CVE-2026-3479
Closing.
Bugzilla
CVE-2026-3479 python3.15: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
bugzilla·2026-03-19
CVE-2026-3479 [NONE] CVE-2026-3479 python3.15: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
CVE-2026-3479 python3.15: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-d494efe6a9 (python3.15-3.15.0~a8-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-d494efe6a9
---
FEDORA-2026-7ea30e843c (python3.15-3.15.0~a8-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-7ea30e843c
---
FEDORA-2026-485183030a (python3.15-3.15.0~a8-1.fc42) has been submitted as an update to Fedora 42.
htt
Bugzilla
CVE-2026-3479 python3.9: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
bugzilla·2026-03-19
CVE-2026-3479 [NONE] CVE-2026-3479 python3.9: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
CVE-2026-3479 python3.9: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This CVE has been disputed: https://www.cve.org/CVERecord?id=CVE-2026-3479
Closing.
Bugzilla
CVE-2026-3479 asahi-installer: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [epel-all]
bugzilla·2026-03-19
CVE-2026-3479 [NONE] CVE-2026-3479 asahi-installer: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [epel-all]
CVE-2026-3479 asahi-installer: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This CVE has been disputed: https://www.cve.org/CVERecord?id=CVE-2026-3479
Closing.
Bugzilla
CVE-2026-3479 python3.11: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
bugzilla·2026-03-19
CVE-2026-3479 [NONE] CVE-2026-3479 python3.11: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
CVE-2026-3479 python3.11: Python pkgutil.get_data(): Path Traversal via improper resource argument validation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This CVE has been disputed: https://www.cve.org/CVERecord?id=CVE-2026-3479
Closing.
Bugzilla
CVE-2026-3479 python: Python pkgutil.get_data(): Path Traversal via improper resource argument validation
bugzilla·2026-03-18
CVE-2026-3479 [NONE] CVE-2026-3479 python: Python pkgutil.get_data(): Path Traversal via improper resource argument validation
CVE-2026-3479 python: Python pkgutil.get_data(): Path Traversal via improper resource argument validation
pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
Wiz
CVE-2025-12781 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2025-12781 [MEDIUM] CVE-2025-12781 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-12781 :
Python Interpreter vulnerability analysis and mitigation
When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alternative base64 alphabet" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.
This behavior can only be insecure if your application uses an alternate base64 alphabet (without "+/"). If your application does not use the "altchars" parameter or
Wiz
CVE-2025-13462 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2025-13462 [LOW] CVE-2025-13462 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-13462 :
Python Interpreter vulnerability analysis and mitigation
The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinterpreted by the tarfile module compared to other implementations.
Source : NVD
## 2
Score
Published March 12, 2026
Severity LOW
CNA Score 2.0
Affected Technologies
Python Interpreter
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python3.14
cpe:2.3:a:python:python
Sources
NVD
Debian 11,
Wiz
CVE-2026-3479 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2026-3479 [LOW] CVE-2026-3479 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3479 :
Python Interpreter vulnerability analysis and mitigation
pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.
Source : NVD
## 2.1
Score
Published March 18, 2026
Severity LOW
CNA Score 2.1
Affected Technologies
Python Interpreter
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python3.14
python3-devel
Sources
NVD
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 20, 2026
Debian 14 No Fix Added at: Mar 20, 2026
Echo Has Fix Added at: Mar 20, 2026
Red Hat 6, 7, 8, 9, 10 Severity LOW No Fix Added at: Mar 20, 2026
Debian Has F
Wiz
CVE-2025-15282 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2025-15282 [LOW] CVE-2025-15282 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15282 :
Python Interpreter vulnerability analysis and mitigation
User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.
Source : NVD
## 6
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
Python Interpreter
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
libpython3_13t1_0
python313-curses
Sources
NVD
Chainguard Has Fix Added at: Jan 28, 2026
Debian 11 Severity MEDIUM Has Fix Added at: Jan 23, 2026
Debian 12, 13 Severity MEDIUM No Fix Added at: Jan 23, 2026
Debian 14 Has Fix Ad
Wiz
CVE-2026-4519 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.0
CVE-2026-4519 [MEDIUM] CVE-2026-4519 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4519 :
Python Interpreter vulnerability analysis and mitigation
The webbrowser.open() API would accept leading dashes in the URL which
could be handled as command line options for certain web browsers. New
behavior rejects leading dashes. Users are recommended to sanitize URLs
prior to passing to webbrowser.open().
Source : NVD
## 7
Score
Published March 20, 2026
Severity HIGH
CNA Score 7.0
Affected Technologies
Python Interpreter
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python39-devel:3.9::python3x-setuptools
python3.13
Sources
NVD
AlmaLinux 8 Severity HIGH Has Fix Added at: A
Wiz
CVE-2025-11468 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.7
CVE-2025-11468 [MEDIUM] CVE-2025-11468 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-11468 :
Python Interpreter vulnerability analysis and mitigation
When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.
Source : NVD
## 5.7
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.7
Affected Technologies
Python Interpreter
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python39-devel:3.9::python39-toml
python39-devel:3.9::python-idna
Sources
NVD
CBL-Mariner 3.0 Severity MEDIUM
Wiz
CVE-2026-0672 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.0
CVE-2026-0672 [MEDIUM] CVE-2026-0672 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0672 :
Python Interpreter vulnerability analysis and mitigation
When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.
Source : NVD
## 6
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
Python Interpreter
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 36.6
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
python3.10-tkinter
python311-devel
Sources
NVD
CBL-Mariner 2.0 Severity MEDIUM Has Fix Added at: Feb 08, 2026
CBL-Mariner 3.0 Severity MEDIUM Has Fix Add
Wiz
CVE-2026-2297 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2026-2297 [LOW] CVE-2026-2297 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2297 :
Python Interpreter vulnerability analysis and mitigation
The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.
Source : NVD
## 5.7
Score
Published March 4, 2026
Severity MEDIUM
CNA Score 5.7
Affected Technologies
Python Interpreter
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python39-devel:3.9::python39-psycopg2-tests
python39-devel:3.9::python-wheel
Sources
NVD
Chainguard Has Fix
Wiz
CVE-2026-4224 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2026-4224 [LOW] CVE-2026-4224 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4224 :
Python Interpreter vulnerability analysis and mitigation
When an Expat parser with a registered ElementDeclHandler parses an inline
document type definition containing a deeply nested content model a C stack
overflow occurs.
Source : NVD
## 6
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
Python Interpreter
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python-3.14
python36:3.6::python3-distro
Sources
NVD
Chainguard Has Fix Added at: Apr 05, 2026
Debian 11, 12, 13 Severity MEDIUM No Fix Added at: Mar 17, 2026
Debian 14 No Fix Added at: Mar 17,
Wiz
CVE-2026-3644 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.0
CVE-2026-3644 [LOW] CVE-2026-3644 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3644 :
Python Interpreter vulnerability analysis and mitigation
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().
Source : NVD
## 6
Score
Published March 16, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
Python Interpreter
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 29.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
python3.11-debug
python39-devel:3.9::m
https://github.com/python/cpython/commit/5af6ce3e7b643a30a02d22245c1e3f4a8bc0a1fehttps://github.com/python/cpython/commit/bcdf231946b1da8bdfbab4c05539bb0cc964a1c7https://github.com/python/cpython/commit/cf59bf76470f3d75ad47d80ffb8ce76b64b5e943https://github.com/python/cpython/commit/d786d59a8f7196bb630100a869f28ad13436b59chttps://github.com/python/cpython/issues/146121https://github.com/python/cpython/pull/146122https://mail.python.org/archives/list/[email protected]/thread/WYLLVQOOCKGK73JM7Z7ZSNOJC4N7BAWY/
2026-03-18
Published