CVE-2026-4519Disclosure(python / python)

LOWCVSS 3.3 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch python python systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • python

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 7d ago at 2 mentions (2026-03-20); latest day: 1
  • 11 total mentions across 8 days

Affected systems

Vendors
Products
python

1 version affected across 1 product

Deep dive

Activity timeline11 mentions / 8d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1Mentions · 2026-03-29: 2Mentions · 2026-03-31: 1Mentions · 2026-04-13: 1Mentions · 2026-04-14: 2Mentions · 2026-04-15: 1Patch / Workaround · 2026-03-29: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-22: 1Technical Details · 2026-03-29: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 103-2003-2103-2203-2903-3104-1304-1404-15
Signal classification3 categories
Disclosure
763.6%
General
327.3%
Patch
19.1%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure1General1
2026-03-211
Disclosure1
2026-03-221
Disclosure1
2026-03-292
Disclosure1Patch1
2026-03-311
General1
2026-04-131
Disclosure1
2026-04-142
Disclosure1General1
2026-04-151
Disclosure1
Full discourse11 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-4786: CPython: Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.⁠open() https://www.openwall.com/lists/oss-security/2026/04/13/11 High severity

    Post summary

    The post announces a new vulnerability in CPython (CVE‑2026‑4786) that allows command injection through webbrowser.open(), noting incomplete mitigation of a related CVE. No exploit, patch, or PoC details are provided.

    10030572
    4.6K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-4519: CPython: webbrowser.⁠open() API allows leading dashes https://www.openwall.com/lists/oss-security/2026/03/20/1 which could be handled as command line options for certain web browsers

    Post summary

    A vulnerability in CPython’s webbrowser.open() allows leading dashes to be interpreted as browser command-line options, potentially leading to unintended actions.

    01030396
    4.4K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Python ❗ CVE-2026-4519 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-python/ https://t.co/2rhGQJpAJH

    Post summary

    The tweet announces a CVE-2026-4519 vulnerability in Python products and links to a site for additional details, but offers no further technical information or actionable content.

    00020275
    6.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🚨 New Research: 68% of enterprises running #Python 3.6 lack URL input validation—exposing them to CVE-2026-4519 command injection risks. Read more: 👉 https://tinyurl.com/ynk3ncss #Security #Fedora https://t.co/BHdq4szGi3

    Post summary

    Researchers highlight that 68% of enterprises using Python 3.6 are exposed to command injection due to missing URL validation (CVE‑2026‑4519). No exploit, patch, or active exploitation details are provided.

    0001063
    1.5K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-4519 impacts python in 6 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/477 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The tweet flags a newly discovered high‑severity CVE affecting AWS Lambda Python base images, providing links to detailed references for further information.

    0000049
    34 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4786 Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "http://webbrowser.open()" API could h… https://www.cve.org/CVERecord?id=CVE-2026-4786

    Post summary

    The text indicates that mitigation for a prior CVE was incomplete and could be bypassed under certain URL conditions, yet it provides no PoC, exploit, or patch information related to CVE-2026-4786.

    0000086
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4786 Incomplete CVE-2026-4519 Mitigation Allows Command Injection via URL Parameters https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4786

    Post summary

    The post references CVE-2026-4786, indicating that its incomplete mitigation permits command injection via URL parameters, but no proof of concept, exploit code, active exploitation, or patch information is provided.

    0000033
    4.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Essential reading for platform engineers: Our comprehensive guide to CVE-2026-4519 covers technical mitigation, business ROI analysis, and compliance mapping. Includes free enterprise security checklist. Read more: 👉 https://tinyurl.com/yx2btjt7 #Fedora #Security https://t.co/JesSOXTfwN

    Post summary

    The tweet promotes a guide on CVE-2026-4519 that outlines mitigation strategies and business impact, but it does not provide exploit details or a PoC.

    0000053
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4519 The http://webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading… https://www.cve.org/CVERecord?id=CVE-2026-4519

    Post summary

    The post announces CVE‑2026‑4519, describing how `webbrowser.open()` could treat leading dashes in URLs as command line options, with updated behavior rejecting this misuse.

    0000073
    56.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4519 Python http://webbrowser.open() API Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4519

    Post summary

    The post merely references the CVE number and a minimal description with a link to a vulnerability database entry, offering no actionable or detailed information.

    0000043
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4519 - http://webbrowser.open() allows leading dashes in URLs Intel Report: https://ift.tt/Db7l6zq

    Post summary

    An advisory alerting to CVE-2026-4519, describing that webbrowser.open() improperly handles URLs with leading dashes, indicating a potential security vulnerability.

    0000036
    334 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonpython---
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--

Explore more