Threats Tagged 'cve-2026-6019'
View all threats tagged with 'cve-2026-6019'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-6019'
Click on any threat for detailed analysis and mitigation recommendations
This update includes the following RPMs: python3.11: * python3.11-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-debug-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-devel-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-idle-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-libs-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-test-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-tkinter-3.11.16-1.1.hum1 (aarch64, x86_64) * python3.11-3.11.16-1.1.hum1.src (src) Security Fix(es): python3.11: * CVE-2026-3446 Join the discussion | GCVE Database | 08/27/2026, 12:58:12 UTC Added: 06/09/2026, 10:23:36 UTC |
A security update for Red Hat Hardened Images includes fixes for vulnerabilities in python3.11 packages. Notably, CVE-2026-3479 addresses a path traversal flaw in Python's pkgutil.get_data() function, which improperly validates resource arguments, allowing local attackers to access files outside intended directories. The advisory notes no current mitigation meets Red Hat's criteria for ease of use and applicability. No explicit patch version is stated in the advisory, but updated RPMs are provided. The vulnerabilities have medium severity. Join the discussion | GCVE Database | 08/20/2026, 18:45:29 UTC Added: 08/22/2026, 13:40:34 UTC |
0 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. Join the discussion | GCVE Database | 06/25/2026, 07:40:44 UTC Added: 06/12/2026, 11:14:24 UTC |
0 Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API (CVE-2026-4786) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 05/20/2026, 11:43:55 UTC Added: 05/27/2026, 21:15:26 UTC |
0 Red Hat has issued a security advisory for python3 in Red Hat Enterprise Linux 8.4 variants addressing two vulnerabilities: CVE-2026-6100, a use-after-free in decompression modules that could lead to arbitrary code execution or information disclosure, and CVE-2026-4786, a command injection vulnerability in the webbrowser.open() API allowing arbitrary code execution. These vulnerabilities affect python3 packages in Red Hat Enterprise Linux 8.4 Advanced Update Support and Extended Update Support. The advisory rates the security impact as Important and provides updated packages to remediate these issues. Join the discussion | GCVE Database | 05/20/2026, 11:36:35 UTC Added: 05/27/2026, 21:15:26 UTC |
0 Red Hat has issued a security advisory for python3.11 addressing two vulnerabilities: CVE-2026-6100, a use-after-free flaw in decompression modules that could lead to arbitrary code execution or information disclosure, and CVE-2026-4786, a command injection vulnerability in the webbrowser.open() API that allows arbitrary code execution. These issues affect Python as packaged in Red Hat Enterprise Linux 9.2 and related variants. The update is rated as important by Red Hat Product Security. No CVSS score is provided in the advisory. The advisory includes updated packages to remediate these vulnerabilities. Join the discussion | GCVE Database | 05/05/2026, 11:18:07 UTC Added: 05/27/2026, 21:15:27 UTC |
0 Red Hat has issued a security advisory for python3.11 in Red Hat Enterprise Linux 8 addressing two vulnerabilities: CVE-2026-6100, a use-after-free in decompression modules leading to arbitrary code execution or information disclosure, and CVE-2026-4786, an arbitrary code execution vulnerability via command injection in the webbrowser.open() API. The update is rated as Important by Red Hat Product Security. The advisory provides updated packages to remediate these issues. Join the discussion | GCVE Database | 04/27/2026, 20:58:25 UTC Added: 05/27/2026, 21:15:27 UTC |
This update includes the following RPMs: python3.13: * python3.13-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-debug-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-devel-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-freethreading-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-freethreading-debug-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-idle-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-libs-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-test-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-tkinter-3.13.13-1.1.hum1 (aarch64, x86_64) * python3.13-3.13.13-1.1.hum1.src (src) Security Fix(es): python3.13: * CVE-2026-1502 * CVE-2026-4786 * CVE-2026-6100 Join the discussion | GCVE Database | 04/23/2026, 11:30:45 UTC Added: 05/27/2026, 21:15:27 UTC |
0 http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value. Join the discussion | CVE Database V5 | 04/22/2026, 19:28:08 UTC Added: 04/22/2026, 20:01:07 UTC |
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details. Join the discussion | GCVE Database | 04/13/2026, 22:16:00 UTC Added: 05/27/2026, 21:15:27 UTC |
Showing 1 to 10 of 11 results