VDB
BIT-PYTHON-2026-4519
BIT-PYTHON-2026-4519
PUBLISHED
CVSS 7 HIGH
A flaw was found in Python. The `webbrowser.open()` API, used to launch web browsers, does not properly sanitize input. This allows a remote attacker to craft a malicious URL containing leading dashes. When such a URL is opened, certain web browsers may interpret these dashes as command-line options, which could lead to unexpected behavior, information disclosure, or potentially arbitrary code execution, impacting the integrity of the system.
Risk Scores
CVSS 4.0
7
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Enterprise Linux 9.4 Extended Update Support | 0:3.11.7-1.el9_4.12 |
| Red Hat | Red Hat Enterprise Linux 8 | |
| Red Hat | Red Hat Enterprise Linux 9 | 0:3.12.13-2.el9_8, 0:3.12.12-4.el9_7.2 |
| Red Hat | Red Hat AI Inference Server 3.3 | 1775680192, 1778274666 |
| Red Hat | Red Hat AI Inference Server 3.3 | 1778244559, 1775749857 |
| Red Hat | Red Hat Enterprise Linux 8 | 0:3.12.12-4.el8_10 |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | 0:3.11.2-2.el8_8.9 |
| Red Hat | Red Hat AI Inference Server 3.3 | 1775680262, 1778244531 |
| Red Hat | RHEL-8 based Middleware Containers | 7.13.5-3.1777325680 |
| Red Hat | Red Hat Update Infrastructure 5 | 1779798222, 1776868842 |
| Red Hat | Red Hat AI Inference Server 3.3 | 1778244546 |
| Red Hat | Red Hat Enterprise Linux AI 3.3 | 1776773505 |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | 0:3.6.8-47.el8_6.12 |
| Red Hat | Red Hat Enterprise Linux 8.6 Telecommunications Update Service | 0:3.6.8-47.el8_6.12 |
| Red Hat | Red Hat AI Inference Server 3.2 | 1779223654, 1775740563 |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | 0:3.6.8-51.el8_8.14 |
| Red Hat | Red Hat Discovery 2 | 1775668717 |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:3.12.9-2.el10_0.8 |
| Red Hat | Red Hat Update Infrastructure 5 | 1776868772, 1779798165 |
| Red Hat | Red Hat Enterprise Linux AI 3.3 | 1776871984 |
…and 45 more
Timeline
- Mar 20, 2026 CVE Published
- Mar 20, 2026 PoC Published
- Mar 23, 2026 PoC Published
- Mar 27, 2026 PoC Published
- Mar 29, 2026 PoC Published
- Mar 29, 2026 PoC Published
- Apr 13, 2026 PoC Published
- Apr 13, 2026 PoC Published
- Apr 13, 2026 PoC Published
- Apr 14, 2026 PoC Published
- Apr 15, 2026 PoC Published
- Apr 17, 2026 PoC Published
References
- https://github.com/python/cpython/pull/143931 patch
- https://github.com/python/cpython/issues/143930 issue
- https://mail.python.org/archives/list/security-announce@python.org/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS/ vendor-advisory
- https://github.com/python/cpython/commit/43fe06b96f6a6cf5cfd5bdab20b8649374956866 patch
- https://github.com/python/cpython/commit/82a24a4442312bdcfc4c799885e8b3e00990f02b patch
- https://github.com/python/cpython/commit/9669a912a0e329c094e992204d6bdb8787024d76 patch
- https://github.com/python/cpython/commit/ad4d5ba32af4d80b0dfa2ba9d8203bfb219e60a5 patch
- https://github.com/python/cpython/commit/ceac1efc66516ac387eef2c9a0ce671895b44f03 patch
- https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48 patch
- https://github.com/python/cpython/commit/3681d47a440865aead912a054d4599087b4270dd patch
- https://github.com/python/cpython/commit/591ed890270c5697b013bf637029fb3e6cd2d73e patch
- https://github.com/python/cpython/commit/594b5a05dc9913880ac92eded440defbf32a28d1 patch
- https://github.com/python/cpython/commit/89bfb8e5ed3c7caa241028f1a4eac5f6275a46a4 patch
- https://github.com/python/cpython/commit/96fc5048605863c7b6fd6289643feb0e97edd96c patch
- https://github.com/python/cpython/commit/cc023511238ad93ecc8796157c6f9139a2bb2932 patch
- http://www.openwall.com/lists/oss-security/2026/03/20/1 url
- https://access.redhat.com/security/cve/CVE-2026-4519 vdb
- RHBZ#2449649 issue
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4519.json url
- https://access.redhat.com/errata/RHSA-2026:10102 vendor-advisory
…and 51 more