
CVE-2026-2297: CPython: SourcelessFileLoader does not use io.open_code() https://www.openwall.com/lists/oss-security/2026/03/05/6 Import hook that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class); sys.audit handlers for this audit event therefore do not fire
Post summary
The post highlights CVE‑2026‑2297, stating that CPython’s SourcelessFileLoader mishandles io.open_code() leading to audit events not firing, but offers no PoC, exploit, patch, or evidence of active exploitation.




