CVE-2026-0864
When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.
Faiblesse
When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.
Produits concernés
- python python
Références
- https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528
- https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd
- https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908
- https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f
- https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98
- https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8
Trouvez la faille avant un attaquant.
Connectez-vous avec GitHub et lancez votre premier audit en moins d'une minute. L'offre gratuite ne nécessite aucune carte bancaire.