CVE-2026-0864: Python

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

Affected products

  • Python Python: before 3.10.21 (fixed in 3.10.21); from 3.11.0, before 3.11.16 (fixed in 3.11.16); from 3.12.0, before 3.12.14 (fixed in 3.12.14); from 3.13.0, before 3.13.15 (fixed in 3.13.15); from 3.14.0, before 3.14.7 (fixed in 3.14.7); version 3.15.0 only

Published 2026-06-23. Last modified 2026-08-18.