CVE-2026-5713
published 2026-04-14CVE-2026-5713: The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features…
PriorityP423medium5.3CVSS 4.0
AVLACHATPPRHUIAVCHVIHVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.13%
3.2th percentile
The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used to read and write addresses in a privileged process if that process connected to a malicious or "infected" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| python_software_foundation | cpython | >= 3.14.0 < 3.14.5 | 3.14.5 |
| python_software_foundation | cpython | >= 3.15.0a1 < 3.15.0b1 | 3.15.0b1 |
| ubuntu | python3.10 | — | — |
| ubuntu | python3.12 | — | — |
| ubuntu | python3.14 | — | — |
CVSS provenance
nvdv4.05.3MEDIUMCVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.3MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 3.3
CVE-2026-9669 [LOW] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly normalized paths in the tarfile
module. An attacker could possibly use this issue to bypass path
restrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (CVE-2025-13462)
It was discovered that Python's HTMLParser incorrectly handled certain
malformed HTML input. An attacker could possibly use this issue to cause
Python to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-69534)
It was discovered that Python's email module incorrectly quoted newlines
in headers. An attacker could possibly use this issue to inject arbitrary
email headers. This issue only affected Ubuntu 22.04 L
Red Hat
python: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process.
vendor_redhat·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CWE-822 python: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process.
python: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process.
A flaw was found in Python. A malicious Python process could exploit the "profiling.sampling" module and "asyncio introspection capabilities" to read and write memory addresses within a privileged process. This vulnerability occurs when the privileged process connects to the malicious process via its remote debugging feature, potentially leading to information disclosure and arbitrary code execution. Successful exploitation requires repeated connections, which may cause instability in the connecting process.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use
VulDB
Python CPython up to 3.14.x profiling.sampling/asyncio stack-based overflow (ID 148178 / Nessus ID 306474)
vuldb·2026-04-24·CVSS 5.3
CVE-2026-5713 [MEDIUM] Python CPython up to 3.14.x profiling.sampling/asyncio stack-based overflow (ID 148178 / Nessus ID 306474)
A vulnerability has been found in Python CPython up to 3.14.x and classified as critical. This issue affects some unknown processing of the component profiling.sampling/asyncio. Performing a manipulation results in stack-based buffer overflow.
This vulnerability is cataloged as CVE-2026-5713. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
GHSA
GHSA-2w92-jcqh-43jc: The "profiling
ghsa_unreviewed·2026-04-14
CVE-2026-5713 [MEDIUM] CWE-121 GHSA-2w92-jcqh-43jc: The "profiling
The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used to read and write addresses in a privileged process if that process connected to a malicious or "infected" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5713 python3.9: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 python3.9: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
CVE-2026-5713 python3.9: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
> The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used...
This does not impact Python 3.9
Bugzilla
CVE-2026-5713 python3.15: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 python3.15: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
CVE-2026-5713 python3.15: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-5713 python3.10: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 python3.10: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
CVE-2026-5713 python3.10: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
> The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used...
This does not impact Python 3.10
Bugzilla
CVE-2026-5713 python: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process.
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 python: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process.
CVE-2026-5713 python: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process.
The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used to read and write addresses in a privileged process if that process connected to a malicious or "infected" Python process via the remote debugging feature. This vulnerability requires persistently and repeatedly connecting to the process to be exploited, even after the connecting process crashes with high likelihood due to ASLR.
Bugzilla
CVE-2026-5713 python3.14: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 python3.14: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
CVE-2026-5713 python3.14: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-5713 mingw-python3: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 mingw-python3: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
CVE-2026-5713 mingw-python3: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
> The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used...
This does not impact Python 3.11
Bugzilla
CVE-2026-5713 python3.13: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [epel-all]
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 python3.13: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [epel-all]
CVE-2026-5713 python3.13: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
> The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used...
This does not impact Python 3.13
Bugzilla
CVE-2026-5713 python3.13: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 python3.13: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
CVE-2026-5713 python3.13: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
> The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used...
This does not impact Python 3.13
Bugzilla
CVE-2026-5713 python3.12: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 python3.12: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
CVE-2026-5713 python3.12: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
> The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used...
This does not impact Python 3.12
Bugzilla
CVE-2026-5713 asahi-installer: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [epel-all]
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 asahi-installer: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [epel-all]
CVE-2026-5713 asahi-installer: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
> The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used...
This does not impact Python 3.13/3.9 used in asahi-installer.
Bugzilla
CVE-2026-5713 python3.6: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 python3.6: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
CVE-2026-5713 python3.6: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
> The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used...
This does not impact Python 3.6
Bugzilla
CVE-2026-5713 asahi-installer: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 asahi-installer: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
CVE-2026-5713 asahi-installer: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
> The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used...
This does not impact Python 3.13/3.9 used in asahi-installer.
Bugzilla
CVE-2026-5713 python3.11: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
bugzilla·2026-04-14·CVSS 5.3
CVE-2026-5713 [MEDIUM] CVE-2026-5713 python3.11: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
CVE-2026-5713 python3.11: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
> The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used...
This does not impact Python 3.11
https://github.com/python/cpython/commit/289fd2c97a7e5aecb8b69f94f5e838ccfeee7e67https://github.com/python/cpython/commit/316f6265b7f9ca4ffed5346b747475ef1943f35dhttps://github.com/python/cpython/issues/148178https://github.com/python/cpython/pull/148187https://mail.python.org/archives/list/[email protected]/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM/http://www.openwall.com/lists/oss-security/2026/04/15/6
2026-04-14
Published