CVE-2026-2297Disclosure

LOWCVSS 5.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-668

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-04); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-03-09: 1Mentions · 2026-04-11: 1Patch / Workaround · 2026-04-11: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-09: 103-0403-0503-0904-11
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure1General1
2026-03-051
General1
2026-03-091
Disclosure1
2026-04-111
Patch1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-2297: CPython: SourcelessFileLoader does not use io⁠.open_code() https://www.openwall.com/lists/oss-security/2026/03/05/6 Import hook that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class); sys.audit handlers for this audit event therefore do not fire

    Post summary

    The post highlights CVE‑2026‑2297, stating that CPython’s SourcelessFileLoader mishandles io.open_code() leading to audit events not firing, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00051442
    4.4K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    #openSUSE just patched two Python CVEs (CVE-2026-2297 & 3479). But local integrity flaws aren't distro-specific. Read more: 👉 https://tinyurl.com/bdrmatdj https://t.co/jErsLq9mRS

    Post summary

    openSUSE has released patches for CVE-2026-2297 and CVE-2026-3479; the tweet makes no mention of PoC, exploit, or active exploitation.

    0001074
    1.5K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-2297 - SourcelessFileLoader does not use http://io.open_code() Intel Report: https://ift.tt/Ao3elSY

    Post summary

    The alert merely cites CVE-2026-2297 with a brief mention of a tool and a URL, providing no PoC, exploit details, active exploitation claim, or patch information.

    0000038
    343 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-2297 The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use http://io.open_code()… https://www.cve.org/CVERecord?id=CVE-2026-2297 ----- Traducción: C… http://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑2297 with a brief description of an import‑hook issue but offers no technical specifics, exploits, or mitigation advice.

    0000061
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2297 The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use http://io.open_code()… https://www.cve.org/CVERecord?id=CVE-2026-2297

    Post summary

    The post discusses a CVE-2026-2297 flaw in CPython’s import hook for legacy *.pyc files, noting that FileLoader improperly handles the code loading function.

    00000449
    56.6K followersView on X

Explore more