PT-2026-51575 · Python · Python

·

CVE-2026-0864

·

Published

2026-06-23

·

Updated

2026-08-28

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Python (affected versions not specified)
Description When using the configparser module to write configuration files containing multi-line text values with carriage return characters (r), the resulting file could be injected with unexpected keys and values if an attacker controls the written value.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-91260
BIT-LIBPYTHON-2026-0864
BIT-PYTHON-2026-0864
BIT-PYTHON-MIN-2026-0864
CVE-2026-0864
ECHO-2EBB-8255-512C
OESA-2026-3068
OESA-2026-3069
OESA-2026-3070
OESA-2026-3071
OESA-2026-3072
OPENSUSE-SU-2026:11426-1
OPENSUSE-SU-2026:11427-1
OPENSUSE-SU-2026:11428-1
OPENSUSE-SU-2026:11429-1
OPENSUSE-SU-2026:11534-1
OPENSUSE-SU-2026:21595-1
PSF-2026-29
SUSE-SU-2026:23159-1
SUSE-SU-2026:23191-1
SUSE-SU-2026:23212-1
SUSE-SU-2026:23303-1
SUSE-SU-2026:3530-1
SUSE-SU-2026:3548-1
SUSE-SU-2026:3560-1
SUSE-SU-2026:3569-1
SUSE-SU-2026:3601-1
SUSE-SU-2026:3635-1
SUSE-SU-2026:3649-1
SUSE-SU-2026:3855-1
SUSE-SU-2026:3862-1

Affected Products

Python