CVE-2026-4519

Python vulnerabilities

Description

A flaw was found in Python. The `webbrowser.open()` API, used to launch web browsers, does not properly sanitize input. This allows a remote attacker to craft a malicious URL containing leading dashes. When such a URL is opened, certain web browsers may interpret these dashes as command-line options, which could lead to unexpected behavior, information disclosure, or potentially arbitrary code execution, impacting the integrity of the system.

Metrics

Severity
high
no public PoC known
7.1
Source: cna-v3
23.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-06 11:48 UTC

Affected operating systems

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    ubuntu / python2.7bionic

  • linux

    ubuntu / python2.7focal

  • linux

    ubuntu / python2.7jammy

  • linux

    ubuntu / python2.7trusty

  • linux

    ubuntu / python2.7xenial

  • linux

    ubuntu / python3.10jammy

  • linux

    ubuntu / python3.11jammy

  • linux

    ubuntu / python3.12noble

  • linux

    ubuntu / python3.14resolute

  • linux

    ubuntu / python3.4trusty

  • linux

    ubuntu / python3.5trusty

  • linux

    ubuntu / python3.5xenial

  • linux

    ubuntu / python3.6bionic

  • linux

    ubuntu / python3.7bionic

  • linux

    ubuntu / python3.8bionic

  • linux

    ubuntu / python3.8focal

  • linux

    ubuntu / python3.9focal

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    python-min3.10.0

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • bitnami

    python-min3.6.0

  • bitnami

    python-min3.7.0

  • bitnami

    python-min3.8.0

  • bitnami

    python-min3.9.0

  • python

    python3.14.0 – 3.14.4

  • python

    python3.13.13

  • python

    python

  • python-markdown

    markdown

References & sources

Linked CVEs

IDCVE-2026-4519
Python vulnerabilities — CVE-2026-4519 | NEOSEC Intel