5.5

CVE-2026-0864

Configuration Injection via Carriage Return (\r) in write() method

When using the "configparser" module to write configuration files
containing multi-line text values with carriage return characters (\r) the
resulting file could be injected with unexpected keys and values if the
attacker controls the written value.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Python ≫ Python Version < 3.10.21
Python ≫ Python Version >= 3.11.0 < 3.11.16
Python ≫ Python Version >= 3.12.0 < 3.12.14
Python ≫ Python Version >= 3.13.0 < 3.13.15
Python ≫ Python Version >= 3.14.0 < 3.14.7
Python ≫ Python Version 3.15.0 Update alpha1
Python ≫ Python Version 3.15.0 Update alpha2
Python ≫ Python Version 3.15.0 Update alpha3
Python ≫ Python Version 3.15.0 Update alpha4
Python ≫ Python Version 3.15.0 Update alpha5
Python ≫ Python Version 3.15.0 Update alpha6
Python ≫ Python Version 3.15.0 Update alpha7
Python ≫ Python Version 3.15.0 Update alpha8
Python ≫ Python Version 3.15.0 Update beta1
Python ≫ Python Version 3.15.0 Update beta2
Python ≫ Python Version 3.15.0 Update beta3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.027
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
cna@python.org 4.1 0 0
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

https://github.com/python/cpython/pull/151559
Patch
Issue Tracking
https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f
Patch
https://github.com/python/cpython/issues/143927
Patch
Issue Tracking
https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528
Patch
https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98
Patch
https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8
Patch
https://mail.python.org/archives/list/security-announce@python.org/thread/CV4NE6AFCRJL7XQOHX7J5TSDHUWVWGJS/
Vendor Advisory
Mailing List
https://github.com/python/cpython/commit/db4a157c790479710a1a840d7937c5c815a6f8b6
Patch
https://github.com/python/cpython/commit/12dcbd74d3563016a8cb8c47e4898889f34f74dd
Patch
https://github.com/python/cpython/commit/274de100bbf4345bd0c23ef5b446722e9e636908
Patch