RHSA-2026:35838: Important: python3 security update
Important: python3 security update
Other sources
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.Security Fix(es): python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API (CVE-2026-4786) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python3to a version that resolves this vulnerability.Fixed in 3.6.8-21.el7_9.6 - Upgrade
Upgrade
redhat/python3-debugto a version that resolves this vulnerability.Fixed in 3.6.8-21.el7_9.6 - Upgrade
Upgrade
redhat/python3-debuginfoto a version that resolves this vulnerability.Fixed in 3.6.8-21.el7_9.6 - Upgrade
Upgrade
redhat/python3-develto a version that resolves this vulnerability.Fixed in 3.6.8-21.el7_9.6 - Upgrade
Upgrade
redhat/python3-idleto a version that resolves this vulnerability.Fixed in 3.6.8-21.el7_9.6 - Upgrade
Upgrade
redhat/python3-libsto a version that resolves this vulnerability.Fixed in 3.6.8-21.el7_9.6 - Upgrade
Upgrade
redhat/python3-testto a version that resolves this vulnerability.Fixed in 3.6.8-21.el7_9.6 - Upgrade
Upgrade
redhat/python3-tkinterto a version that resolves this vulnerability.Fixed in 3.6.8-21.el7_9.6 - Compensating control
Mitigate the CVE-2026-4786 risk by preventing untrusted input from reaching the Python cpython webbrowser.open() API that could trigger command injection (arbitrary code execution).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:35838?
The severity of RHSA-2026:35838 is classified as high with a score of 7.
What does the RHSA-2026:35838 vulnerability pertain to?
RHSA-2026:35838 pertains to a security update for python3 in Red Hat Enterprise Linux Server.
How do I fix RHSA-2026:35838?
To fix RHSA-2026:35838, apply the latest python3 security update from Red Hat.
What software is affected by RHSA-2026:35838?
RHSA-2026:35838 affects Red Hat Enterprise Linux Server for IBM Power (big/little endian) and IBM z Systems.
When was RHSA-2026:35838 published?
RHSA-2026:35838 was published on July 6, 2026.