VDB

BIT-LIBPYTHON-2026-4519

BIT-LIBPYTHON-2026-4519 PUBLISHED CVSS 7 HIGH

A flaw was found in Python. The `webbrowser.open()` API, used to launch web browsers, does not properly sanitize input. This allows a remote attacker to craft a malicious URL containing leading dashes. When such a URL is opened, certain web browsers may interpret these dashes as command-line options, which could lead to unexpected behavior, information disclosure, or potentially arbitrary code execution, impacting the integrity of the system.

Risk Scores

CVSS 4.0
7
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Red HatRed Hat AI Inference Server 3.31778244559, 1775749857
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:3.9.21-2.el9_6.5
Red HatRed Hat Enterprise Linux 90:3.11.13-9.el9_8, 0:3.11.13-5.2.el9_7
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support0:2.7.5-94.el7_9.4
Red HatRed Hat Enterprise Linux 8.6 Update Services for SAP Solutions0:3.6.8-47.el8_6.12
Red HatRed Hat Hardened Images3.13.13-1.hum1
Red HatRed Hat Enterprise Linux 80:3.12.12-4.el8_10
Red HatRed Hat Enterprise Linux 80:3.6.8-75.el8_10
Red HatRed Hat AI Inference Server 3.31778244531, 1775680262
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:3.12.9-2.el10_0.8
Red HatRed Hat Enterprise Linux 100:3.12.13-2.el10_2, 0:3.12.12-3.el10_1.2
Red HatRHEL-8 based Middleware Containers7.13.5-4.1777325710
Red HatRed Hat Enterprise Linux AI 3.31776871984
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:3.6.8-51.el8_8.14
Red HatRed Hat Enterprise Linux 8.8 Update Services for SAP Solutions0:3.6.8-51.el8_8.14
Red HatRed Hat Enterprise Linux 9.4 Extended Update Support0:3.12.1-4.el9_4.12
Red HatRHEL-8 based Middleware Containers7.13.5-4.1777325708
Red HatRed Hat AI Inference Server 3.31775680192, 1778274666
Red HatRed Hat Enterprise Linux 8.6 Telecommunications Update Service0:3.6.8-47.el8_6.12
Red HatRed Hat Enterprise Linux 8.8 Telecommunications Update Service0:3.11.2-2.el8_8.9

…and 45 more

Timeline

  • Mar 20, 2026 CVE Published
  • Mar 20, 2026 PoC Published
  • Mar 23, 2026 PoC Published
  • Mar 27, 2026 PoC Published
  • Mar 29, 2026 PoC Published
  • Mar 29, 2026 PoC Published
  • Apr 13, 2026 PoC Published
  • Apr 13, 2026 PoC Published
  • Apr 13, 2026 PoC Published
  • Apr 14, 2026 PoC Published
  • Apr 15, 2026 PoC Published
  • Apr 17, 2026 PoC Published

References

…and 51 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›