Skip to main content

Threats Tagged 'cve-2026-6019'

View all threats tagged with 'cve-2026-6019'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-6019

Threats Tagged 'cve-2026-6019'

Click on any threat for detailed analysis and mitigation recommendations

This update includes the following RPMs: python3.11: * python3.11-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-debug-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-devel-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-idle-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-libs-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-test-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-tkinter-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-3.11.16-1.1.hum1.src (src) Security Fix(es): python3.11: * CVE-2026-3446

Join the discussion

A security update for Red Hat Hardened Images includes fixes for vulnerabilities in python3.11 packages. Notably, CVE-2026-3479 addresses a path traversal flaw in Python's pkgutil.get_data() function, which improperly validates resource arguments, allowing local attackers to access files outside intended directories. The advisory notes no current mitigation meets Red Hat's criteria for ease of use and applicability. No explicit patch version is stated in the advisory, but updated RPMs are provided. The vulnerabilities have medium severity.

Join the discussion

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

Join the discussion
0

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API (CVE-2026-4786) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

Red Hat has issued a security advisory for python3 in Red Hat Enterprise Linux 8.4 variants addressing two vulnerabilities: CVE-2026-6100, a use-after-free in decompression modules that could lead to arbitrary code execution or information disclosure, and CVE-2026-4786, a command injection vulnerability in the webbrowser.open() API allowing arbitrary code execution. These vulnerabilities affect python3 packages in Red Hat Enterprise Linux 8.4 Advanced Update Support and Extended Update Support. The advisory rates the security impact as Important and provides updated packages to remediate these issues.

Join the discussion
0

Red Hat has issued a security advisory for python3.11 addressing two vulnerabilities: CVE-2026-6100, a use-after-free flaw in decompression modules that could lead to arbitrary code execution or information disclosure, and CVE-2026-4786, a command injection vulnerability in the webbrowser.open() API that allows arbitrary code execution. These issues affect Python as packaged in Red Hat Enterprise Linux 9.2 and related variants. The update is rated as important by Red Hat Product Security. No CVSS score is provided in the advisory. The advisory includes updated packages to remediate these vulnerabilities.

Join the discussion
0

Red Hat has issued a security advisory for python3.11 in Red Hat Enterprise Linux 8 addressing two vulnerabilities: CVE-2026-6100, a use-after-free in decompression modules leading to arbitrary code execution or information disclosure, and CVE-2026-4786, an arbitrary code execution vulnerability via command injection in the webbrowser.open() API. The update is rated as Important by Red Hat Product Security. The advisory provides updated packages to remediate these issues.

Join the discussion

This update includes the following RPMs: python3.13: * python3.13-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-debug-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-devel-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-freethreading-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-freethreading-debug-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-idle-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-libs-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-test-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-tkinter-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-3.13.13-1.1.hum1.src (src) Security Fix(es): python3.13: * CVE-2026-1502 * CVE-2026-4786 * CVE-2026-6100

Join the discussion

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

Join the discussion

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

Join the discussion

Showing 1 to 10 of 11 results

Filters:Tag: cve-2026-6019
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses