ThreatCluster[verified]@threatclusterPatch
SUSE has issued critical patches for several Python3-related CVEs that allow command injection and code execution on openSUSE systems.
ThreatCluster[verified]@threatclusterPatch
Fedora released a patch for python3 addressing several CVEs that could lead to code execution, data leaks, and HTTP header injection.
Open Source Security mailing list@oss_securityDisclosure
A new CVE (CVE‑2026‑4786) affecting CPython is announced, highlighting a command injection flaw in the webbrowser.open() function with an incomplete earlier mitigation, and classified as high severity.
Ferramentas Linux@Cezar_H_LinuxPatch
A Rocky Linux 10 advisory (RLSA-2026:28581) announces patches for two CVEs, including a command‑injection flaw, with additional details via a linked resource.
Ferramentas Linux@Cezar_H_LinuxDisclosure
The tweet announces new CVEs affecting Python 3.14 on Fedora, noting their types as HTTP and command injection, without providing PoC, exploitation details, or patch information.
Rob Savoury@RobSavouryPatch
A new Python 3.14.5 package is now available on the SavOS PPA, providing patches for CVE‑2026‑1502, CVE‑2026‑4786, and CVE‑2026‑5713 for Ubuntu Linux users.
CVE@CVEnewGeneral
The note indicates the mitigation for CVE‑2026‑4519 was incomplete and that URLs containing "%action" could bypass the protection on certain browsers, but provides no additional technical details or mitigation information.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The brief entry references CVE‑2026‑4786 and links to a vulnerability detail page but provides no evidence of a PoC, active exploitation, patch, or technical specifics.