When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.
CVSS Details
- CVSS 4.0 Base Score: 4.1 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade python3 | Aug 17, 2026 | Jun 23, 2026 |
| Amazon_linux_2023 | — | Upgrade python3.13Upgrade python3.11-debugUpgrade python3.11-testUpgrade python3-libsUpgrade python3.11Upgrade python3.14-freethreading-libsUpgrade python3.9-debugsourceUpgrade python3.14Upgrade python3.14-freethreading-develUpgrade python3.14-develUpgrade python3.14-debugsourceUpgrade python3.13-testUpgrade python3.11-develUpgrade python3.11-tkinterUpgrade python3.13-libsUpgrade python3.14-testUpgrade python3.14-freethreading-testUpgrade python-unversioned-commandUpgrade python3.13-debugsourceUpgrade python3-testUpgrade python3.13-idleUpgrade python3.13-debugUpgrade python3.13-freethreadingUpgrade python3.13-develUpgrade python3.11-libsUpgrade python3.14-idleUpgrade python3.11-debuginfoUpgrade python3.13-debuginfoUpgrade python3Upgrade python3.13-tkinterUpgrade python3-idleUpgrade python3.14-tkinterUpgrade python3.14-freethreading-idleUpgrade python3.9-debuginfoUpgrade python3.14-libsUpgrade python3.13-freethreading-debugUpgrade python3.11-debugsourceUpgrade python3-develUpgrade python3.14-freethreading-tkinterUpgrade python3.14-freethreadingUpgrade python3.11-idleUpgrade python3.14-debugUpgrade python3-tkinterUpgrade python3-debugUpgrade python3.14-freethreading-debugUpgrade python3.14-debuginfo | Jul 21, 2026 | Jun 23, 2026 |
| Debian | — | Upgrade python3.13 | Sep 21, 2026 | Jun 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jun 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub