VDB
BIT-LIBPYTHON-2026-4519
BIT-LIBPYTHON-2026-4519
PUBLISHED
CVSS 7 HIGH
A flaw was found in Python. The `webbrowser.open()` API, used to launch web browsers, does not properly sanitize input. This allows a remote attacker to craft a malicious URL containing leading dashes. When such a URL is opened, certain web browsers may interpret these dashes as command-line options, which could lead to unexpected behavior, information disclosure, or potentially arbitrary code execution, impacting the integrity of the system.
Risk Scores
CVSS 4.0
7
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat AI Inference Server 3.3 | 1778244559, 1775749857 |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:3.9.21-2.el9_6.5 |
| Red Hat | Red Hat Enterprise Linux 9 | 0:3.11.13-9.el9_8, 0:3.11.13-5.2.el9_7 |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | 0:2.7.5-94.el7_9.4 |
| Red Hat | Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | 0:3.6.8-47.el8_6.12 |
| Red Hat | Red Hat Hardened Images | 3.13.13-1.hum1 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:3.12.12-4.el8_10 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:3.6.8-75.el8_10 |
| Red Hat | Red Hat AI Inference Server 3.3 | 1778244531, 1775680262 |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:3.12.9-2.el10_0.8 |
| Red Hat | Red Hat Enterprise Linux 10 | 0:3.12.13-2.el10_2, 0:3.12.12-3.el10_1.2 |
| Red Hat | RHEL-8 based Middleware Containers | 7.13.5-4.1777325710 |
| Red Hat | Red Hat Enterprise Linux AI 3.3 | 1776871984 |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:3.6.8-51.el8_8.14 |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:3.6.8-51.el8_8.14 |
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | 0:3.12.1-4.el9_4.12 |
| Red Hat | RHEL-8 based Middleware Containers | 7.13.5-4.1777325708 |
| Red Hat | Red Hat AI Inference Server 3.3 | 1775680192, 1778274666 |
| Red Hat | Red Hat Enterprise Linux 8.6 Telecommunications Update Service | 0:3.6.8-47.el8_6.12 |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:3.11.2-2.el8_8.9 |
…and 45 more
Timeline
- Mar 20, 2026 CVE Published
- Mar 20, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 27, 2026 PoC Published
- Mar 29, 2026 PoC Published
- Mar 29, 2026 PoC Published
- Apr 13, 2026 PoC Published
- Apr 13, 2026 PoC Published
- Apr 13, 2026 PoC Published
- Apr 14, 2026 PoC Published
- Apr 15, 2026 PoC Published
- Apr 17, 2026 PoC Published
References
- https://github.com/python/cpython/pull/143931 patch
- https://github.com/python/cpython/issues/143930 issue
- https://mail.python.org/archives/list/security-announce@python.org/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS/ vendor-advisory
- https://github.com/python/cpython/commit/43fe06b96f6a6cf5cfd5bdab20b8649374956866 patch
- https://github.com/python/cpython/commit/82a24a4442312bdcfc4c799885e8b3e00990f02b patch
- https://github.com/python/cpython/commit/9669a912a0e329c094e992204d6bdb8787024d76 patch
- https://github.com/python/cpython/commit/ad4d5ba32af4d80b0dfa2ba9d8203bfb219e60a5 patch
- https://github.com/python/cpython/commit/ceac1efc66516ac387eef2c9a0ce671895b44f03 patch
- https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48 patch
- https://github.com/python/cpython/commit/3681d47a440865aead912a054d4599087b4270dd patch
- https://github.com/python/cpython/commit/591ed890270c5697b013bf637029fb3e6cd2d73e patch
- https://github.com/python/cpython/commit/594b5a05dc9913880ac92eded440defbf32a28d1 patch
- https://github.com/python/cpython/commit/89bfb8e5ed3c7caa241028f1a4eac5f6275a46a4 patch
- https://github.com/python/cpython/commit/96fc5048605863c7b6fd6289643feb0e97edd96c patch
- https://github.com/python/cpython/commit/cc023511238ad93ecc8796157c6f9139a2bb2932 patch
- http://www.openwall.com/lists/oss-security/2026/03/20/1 url
- https://access.redhat.com/security/cve/CVE-2026-4519 vdb
- RHBZ#2449649 issue
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4519.json url
- https://access.redhat.com/errata/RHSA-2026:10102 vendor-advisory
…and 51 more