ZeroHour
Product

Python

1 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

USN-8744-1: Python vulnerabilities

Ubuntu issued USN-8744-1 fixing CVE-2026-3644, a Python http.cookies content-injection flaw, plus a pyexpat recursion DoS across six Ubuntu LTS releases.

Ubuntu published security notice USN-8744-1 addressing two Python vulnerabilities affecting Ubuntu 14.04 LTS through 24.04 LTS. CVE-2026-3644 concerns incorrect handling of control characters in the http.cookies module, which could allow an attacker to inject arbitrary content. The second issue involves unbounded recursion in the Expat XML parser reached via the pyexpat module, which could crash Python and cause a denial of service. Updated packages are available; no exploitation in the wild is reported.

Ubuntu Security Noticesupdated · 4d agofirst · 5d agoAdvisory 13 sourcesCVE-2026-36441

Python 3.15.0 candidate 2 is here!

Python 3.15.0 release candidate 2 arrives, locking changes to bug fixes ahead of the final October release.

Hugo van Kemenade, release manager for Python 3.14 and 3.15, announced the final release candidate for Python 3.15. Only reviewed bug fixes are allowed between this candidate and the final release scheduled for October. Third-party maintainers are encouraged to test against 3.15 and publish wheels on PyPI.

Simon Willison · 14d agoOther

Related CVEs

  • The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete.
    The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().
    · python python

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.