REDHAT-BUG-2458049: High severity Python CPython vulnerability

Published Apr 13, 2026
·
Updated

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

Affected Software

2 affected components
Python CPython
redhat/python3

Event History

Apr 13, 2026
Data Sourced
via Red Hat·10:02 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2458049?

The severity of REDHAT-BUG-2458049 is critical due to the possibility of command injection via the webbrowser.open() API.

2

How do I fix REDHAT-BUG-2458049?

To fix REDHAT-BUG-2458049, ensure that you have the latest security updates and patches applied to your Python and Red Hat software.

3

What types of software are affected by REDHAT-BUG-2458049?

REDHAT-BUG-2458049 affects Python CPython and redhat/python3 implementations.

4

What is the impact of REDHAT-BUG-2458049?

The impact of REDHAT-BUG-2458049 includes potential command injection vulnerabilities, allowing attackers to execute arbitrary commands on the underlying shell.

5

Is there a workaround for REDHAT-BUG-2458049?

Currently, there is no defined workaround for REDHAT-BUG-2458049 aside from applying the recommended patches and updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203