REDHAT-BUG-2455413: High severity CPython vulnerability
Published Apr 6, 2026
·Updated
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attributefilter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
Affected Software
1 affected component
CPython<=2.6
Event History
Apr 6, 2026
Data Sourced
via Red Hat·04:03 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2455413?
The severity of REDHAT-BUG-2455413 is high with a rating of 7.
2
How do I fix REDHAT-BUG-2455413?
To fix REDHAT-BUG-2455413, update your CPython to a version later than 2.6 where the bug has been resolved.
3
What are the potential impacts of REDHAT-BUG-2455413?
The potential impacts of REDHAT-BUG-2455413 include arbitrary code execution due to the bypass of attribute filters.
4
In which versions of CPython does REDHAT-BUG-2455413 exist?
REDHAT-BUG-2455413 exists in CPython version 2.6 and earlier.
5
What components are affected by REDHAT-BUG-2455413?
REDHAT-BUG-2455413 affects the Lupa integration of Lua or LuaJIT2 into CPython.