PT-2026-32696 · Python+4 · Cpython+4

·

CVE-2026-5713

·

Published

2026-04-06

·

Updated

2026-07-31

CVSS v2.0

5.5

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions CPython versions 3.14 and later
Description The profiling.sampling module and asyncio introspection capabilities, specifically the 'python -m asyncio ps' and 'python -m asyncio pstree' commands, allow for out-of-bounds read and write operations of addresses in a privileged process. This occurs if the privileged process connects to a malicious Python process through the remote debugging feature. Exploitation requires persistent and repeated connections to the process, as Address Space Layout Randomization (ASLR)—a security technique that randomly arranges the address space positions of key data areas of a process—makes the connecting process likely to crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Stack Overflow

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:19019
ALSA-2026:19176
BDU:2026-08065
BIT-LIBPYTHON-2026-5713
BIT-PYTHON-2026-5713
BIT-PYTHON-MIN-2026-5713
CVE-2026-5713
OPENSUSE-SU-2026:10648-1
OPENSUSE-SU-2026:11181-1
PSF-2026-19
RHSA-2026:19019
RHSA-2026:19176
RHSA-2026:7443
RHSA-2026:8822
RHSA-2026:8824
RHSA-2026:9228
USN-8509-1

Affected Products

Cpython
Linuxmint
Red Os
Rocky Linux
Ubuntu