CVE-2026-4786: Python Software Foundation Cpython

High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

Affected products

  • Python Software Foundation Cpython: before 3.10.21 (fixed in 3.10.21); from 3.11.0, before 3.11.16 (fixed in 3.11.16); from 3.12.0, before 3.12.14 (fixed in 3.12.14); from 3.13.0, before 3.13.14 (fixed in 3.13.14); from 3.14.0a1, before 3.14.5rc1 (fixed in 3.14.5rc1); from 3.15.0a1, before 3.15.0b1 (fixed in 3.15.0b1)
  • Red Hat Red Hat Ai Inference Server 3.2: before 1780681984 (fixed in 1780681984)
  • Red Hat Red Hat Ai Inference Server 3.3: before 1782352950 (fixed in 1782352950); before 1782352919 (fixed in 1782352919); before 1782353093 (fixed in 1782353093); before 1782352847 (fixed in 1782352847)
  • Red Hat Red Hat Enterprise Linux 10: before 0:3.12.12-3.el10_1.3 (fixed in 0:3.12.12-3.el10_1.3); before 0:3.14.4-2.el10_2 (fixed in 0:3.14.4-2.el10_2)
  • Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:3.12.9-2.el10_0.9 (fixed in 0:3.12.9-2.el10_0.9)
  • Red Hat Red Hat Enterprise Linux 6 Extended Lifecycle Support - Extension: before 0:2.6.6-70.el6_10.4 (fixed in 0:2.6.6-70.el6_10.4)
  • Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:2.7.5-94.el7_9.5 (fixed in 0:2.7.5-94.el7_9.5); before 0:3.6.8-21.el7_9.6 (fixed in 0:3.6.8-21.el7_9.6)
  • Red Hat Red Hat Enterprise Linux 8: before 0:3.12.13-2.el8_10 (fixed in 0:3.12.13-2.el8_10); before 0:3.11.13-7.el8_10 (fixed in 0:3.11.13-7.el8_10); before 0:3.6.8-76.el8_10 (fixed in 0:3.6.8-76.el8_10)
  • Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:3.6.8-39.el8_4.11 (fixed in 0:3.6.8-39.el8_4.11)
  • Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:3.6.8-39.el8_4.11 (fixed in 0:3.6.8-39.el8_4.11)
  • Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:3.6.8-47.el8_6.13 (fixed in 0:3.6.8-47.el8_6.13)
  • Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 0:3.6.8-47.el8_6.13 (fixed in 0:3.6.8-47.el8_6.13)
  • Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 0:3.6.8-47.el8_6.13 (fixed in 0:3.6.8-47.el8_6.13)
  • Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:3.6.8-51.el8_8.15 (fixed in 0:3.6.8-51.el8_8.15); before 0:3.11.2-2.el8_8.10 (fixed in 0:3.11.2-2.el8_8.10)
  • Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:3.6.8-51.el8_8.15 (fixed in 0:3.6.8-51.el8_8.15); before 0:3.11.2-2.el8_8.10 (fixed in 0:3.11.2-2.el8_8.10)
  • Red Hat Red Hat Enterprise Linux 9: before 0:3.12.12-4.el9_7.3 (fixed in 0:3.12.12-4.el9_7.3); before 0:3.11.13-5.3.el9_7 (fixed in 0:3.11.13-5.3.el9_7); before 0:3.9.25-3.el9_7.3 (fixed in 0:3.9.25-3.el9_7.3); before 0:3.14.4-2.el9_8 (fixed in 0:3.14.4-2.el9_8)
  • Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:3.9.10-4.el9_0.11 (fixed in 0:3.9.10-4.el9_0.11)
  • Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:3.11.2-2.el9_2.12 (fixed in 0:3.11.2-2.el9_2.12); before 0:3.9.16-1.el9_2.14 (fixed in 0:3.9.16-1.el9_2.14)
  • Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:3.11.7-1.el9_4.13 (fixed in 0:3.11.7-1.el9_4.13); before 0:3.12.1-4.el9_4.13 (fixed in 0:3.12.1-4.el9_4.13); before 0:3.9.18-3.el9_4.13 (fixed in 0:3.9.18-3.el9_4.13)
  • Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:3.11.11-2.el9_6.7 (fixed in 0:3.11.11-2.el9_6.7); before 0:3.12.9-1.el9_6.8 (fixed in 0:3.12.9-1.el9_6.8); before 0:3.9.21-2.el9_6.6 (fixed in 0:3.9.21-2.el9_6.6)
  • Red Hat Red Hat Enterprise Linux Ai 3.3: before 1776871984 (fixed in 1776871984); before 1776871985 (fixed in 1776871985); before 1776872005 (fixed in 1776872005); before 1776773390 (fixed in 1776773390); before 1776871987 (fixed in 1776871987); before 1776773505 (fixed in 1776773505); …
  • Red Hat Red Hat Hardened Images: before 3.13.13-1.1.hum1 (fixed in 3.13.13-1.1.hum1); before 3.11.15-4.hum1 (fixed in 3.11.15-4.hum1); before 3.12.13-3.hum1 (fixed in 3.12.13-3.hum1); before 3.14.4-2.hum1 (fixed in 3.14.4-2.hum1)
  • Red Hat Red Hat Update Infrastructure 5: before 1777459441 (fixed in 1777459441); before 1777454300 (fixed in 1777454300); before 1777459504 (fixed in 1777459504); before 1779798159 (fixed in 1779798159); before 1779798164 (fixed in 1779798164); before 1779798165 (fixed in 1779798165); …
  • Red Hat Rhel-8 Based Middleware Containers: before 7.13.5-4.1777325677 (fixed in 7.13.5-4.1777325677); before 7.13.5-4.1777325711 (fixed in 7.13.5-4.1777325711); before 7.13.5-4.1777325710 (fixed in 7.13.5-4.1777325710); before 7.13.5-3.1777325680 (fixed in 7.13.5-3.1777325680); before 7.13.5-4.1777325709 (fixed in 7.13.5-4.1777325709); before 7.13.5-4.1777325680 (fixed in 7.13.5-4.1777325680); …

Published 2026-04-13. Last modified 2026-08-13.