CVE-2026-3298: Python Software Foundation Cpython

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected.

Affected products

  • Python Software Foundation Cpython: before 3.11.16 (fixed in 3.11.16); from 3.12.0, before 3.12.14 (fixed in 3.12.14); from 3.13.0, before 3.13.14 (fixed in 3.13.14); from 3.14.0a1, before 3.14.5rc1 (fixed in 3.14.5rc1); from 3.15.0a1, before 3.15.0b1 (fixed in 3.15.0b1)

Published 2026-04-21. Last modified 2026-08-13.