CVE-2026-3298Disclosure

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allowed for an out-of-bounds buffer write if data was larger than the buffer size. Non-Windows platforms are not affected.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • Exploit: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-04-21); latest day: 1
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-04-21: 2Mentions · 2026-04-23: 1Mentions · 2026-04-24: 2Mentions · 2026-04-27: 1Mentions · 2026-04-30: 1PoC Mentioned / Linked · 2026-04-24: 1Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-23: 1Technical Details · 2026-04-24: 2Technical Details · 2026-04-27: 1Technical Details · 2026-04-30: 104-2104-2304-2404-2704-30
Signal classification2 categories
Disclosure
685.7%
Exploit
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-212
Disclosure2
2026-04-231
Disclosure1
2026-04-242
Disclosure1Exploit1
2026-04-271
Disclosure1
2026-04-301
Disclosure1
Full discourse7 posts
  • Gray Hats@the_yellow_fall
    Disclosure

    Python’s asyncio on Windows faces a high-severity RCE (CVE-2026-3298). A missing boundary check in ProacterEventLoop risks memory corruption. Update now. #Python #asyncio #WindowsSecurity #CVE20263298 #InfoSec #CyberSecurity #PatchNow https://securityonline.info/python-asyncio-windows-vulnerability-cve-2026-3298/ https://t.co/4BRze1THow

    Post summary

    A new high‑severity RCE vulnerability (CVE-2026-3298) affecting Python’s asyncio on Windows has been disclosed, stemming from a missing boundary check that causes memory corruption; users are urged to apply the available patch.

    31082723
    12.5K followersView on X
  • Hunt.io@Huntio
    Disclosure

    ⚠️ Python asyncio Flaw Exposes Windows Systems https://cyberpress.org/critical-python-vulnerability/ Python’s asyncio module has a high-severity Windows-only flaw tracked as CVE-2026-3298. The issue affects sock_recvfrom_into() in asyncio.ProactorEventLoop, the default Windows event loop since Python 3.8. A missing boundary check on the nbytes parameter can let oversized network data overwrite memory, risking crashes, data corruption, or potential code execution. #Python #CyberSecurity #InfoSec #Windows

    Post summary

    The article announces a high‑severity Windows‑only flaw in Python’s asyncio module (CVE‑2026‑3298), detailing the boundary‑check vulnerability and its potential for memory overwrite and code execution, but does not mention PoCs, exploits, active use, or patches.

    02014653
    6.5K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Python asyncio モジュールの脆弱性 CVE-2026-3298 が FIX:Windows 環境におけるメモリ破壊 https://iototsecnews.jp/2026/04/24/python-vulnerability-enables-out-of-bounds-write-on-windows/ この問題の根本的な原因は、Python の非同期通信を担う asyncio モジュールの特定の機能 (sock_recvfrom_into) において、受け取るデータの大きさを正しく制限する仕組みが欠落していたことにあります。具体的には CVE-2026-3298 として識別されており、あらかじめ用意したメモリの枠 (バッファ) を超えるデータが届いた際も、その枠をはみ出して隣のデータを書き換えてしまう “境界外書き込み” (OOB 書き込み) が発生します。これにより、プログラムが異常終了したり、本来動くはずのない悪意ある命令が実行されたりするリスクが生じます。ご利用のチームは、ご注意ください。 #asyncio #CVE20263298 #Python #Vulnerability

    Post summary

    The post announces CVE‑2026‑3298, a Windows‑specific out‑of‑bounds write vulnerability in Python’s asyncio module, detailing the affected function and consequences, but it does not provide PoC, exploit, or patch information.

    0100099
    485 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Exploit

    🚨 #CVE-2026-3298: Critical #Python asyncio Out-of-Bounds Write on #Windows – Exploit Analysis & Mitigation Guide + Video https://undercodetesting.com/cve-2026-3298-critical-python-asyncio-out-of-bounds-write-on-windows-exploit-analysis-mitigation-guide-video/ Educational Purposes!

    Post summary

    The tweet links to a video guide that includes exploit analysis and mitigation steps for CVE‑2026‑3298, providing technical details and a workaround but no explicit exploit code or evidence of active exploitation.

    0000053
    497 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: High severity CVE-2026-3298 in Python asyncio on Windows allows out-of-bounds writes via sock_recvfrom_into, exposing apps to potential remote code execution. https://threatcluster.io/cluster/high-severity-python-vulnerability-discovered-in-windows-asy-52d42cf9

    Post summary

    The post announces CVE-2026-3298, a high‑severity out‑of‑bounds write vulnerability in Python asyncio on Windows that could lead to remote code execution. No PoC, exploit, or mitigation details are offered.

    0000051
    160 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3298 The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allow… https://www.cve.org/CVERecord?id=CVE-2026-3298 ----- Traducción: CVE-2026-3298 El … http://infoflow.cloud`

    Post summary

    The text discloses CVE-2026-3298, describing a missing boundary check in the asyncio.ProactorEventLoop’s sock_recvfrom_into() method on Windows, which could lead to a buffer overrun. No exploit, Patch or active exploitation information is provided.

    0000029
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3298 The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. This allow… https://www.cve.org/CVERecord?id=CVE-2026-3298

    Post summary

    The post announces CVE‑2026‑3298, detailing a boundary‑check omission in asyncio.ProacterEventLoop’s sock_recvfrom_into() on Windows, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    00000150
    57.2K followersView on X

Explore more