REDHAT-BUG-2458049: High severity Python CPython vulnerability
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2458049?
The severity of REDHAT-BUG-2458049 is critical due to the possibility of command injection via the webbrowser.open() API.
How do I fix REDHAT-BUG-2458049?
To fix REDHAT-BUG-2458049, ensure that you have the latest security updates and patches applied to your Python and Red Hat software.
What types of software are affected by REDHAT-BUG-2458049?
REDHAT-BUG-2458049 affects Python CPython and redhat/python3 implementations.
What is the impact of REDHAT-BUG-2458049?
The impact of REDHAT-BUG-2458049 includes potential command injection vulnerabilities, allowing attackers to execute arbitrary commands on the underlying shell.
Is there a workaround for REDHAT-BUG-2458049?
Currently, there is no defined workaround for REDHAT-BUG-2458049 aside from applying the recommended patches and updates.