CVE-2026-2297: Python Software Foundation Cpython
Medium severity, CVSS 5.7. EPSS: 0.2% chance of exploitation in the next 30 days.
The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.
Affected products
- Python Software Foundation Cpython: before 3.10.21 (fixed in 3.10.21); from 3.11.0, before 3.11.16 (fixed in 3.11.16); from 3.12.0, before 3.12.14 (fixed in 3.12.14); from 3.13.0, before 3.13.13 (fixed in 3.13.13); from 3.14.0, before 3.14.4 (fixed in 3.14.4); from 3.15.0a1, before 3.15.0a7 (fixed in 3.15.0a7)
Published 2026-03-04. Last modified 2026-08-13.