← Back

CVE-2026-0864

nvd nist
Published: Jun 23, 2026Modified: Aug 18, 2026

JSON object

Loading...
4.1
Vector
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: CNA (Secondary)

Description

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

Affected (16)

Products: Python: Python
1 product
Python
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Python
Before 3.10.21
From 3.11.0 to 3.11.16
From 3.12.0 to 3.12.14
From 3.13.0 to 3.13.15
From 3.14.0 to 3.14.7
Version 3.15.0 alpha1
Version 3.15.0 alpha2
Version 3.15.0 alpha3
Version 3.15.0 alpha4
Version 3.15.0 alpha5
Version 3.15.0 alpha6
Version 3.15.0 alpha7
Version 3.15.0 alpha8
Version 3.15.0 beta1
Version 3.15.0 beta2
Version 3.15.0 beta3

Timeline

No history available yet.