CVE-2026-4519
The webbrowser.open() API would accept leading dashes in the URL which
could be handled as command line options for certain web browsers. New
behavior rejects leading dashes. Users are recommended to sanitize URLs
prior to passing to webbrowser.open().
could be handled as command line options for certain web browsers. New
behavior rejects leading dashes. Users are recommended to sanitize URLs
prior to passing to webbrowser.open().
Vendor
-
Product
-
CWE
Yayın Tarihi
2026-03-20 15:16:24
Güncelleme
2026-03-25 18:16:33
Source Identifier
cna@python.org
KEV Date Added
-
Kategoriler
Referanslar
https://github.com/python/cpython/commit/43fe06b96f6a6cf5cfd5bdab20b8649374956866
https://github.com/python/cpython/commit/82a24a4442312bdcfc4c799885e8b3e00990f02b
https://github.com/python/cpython/commit/9669a912a0e329c094e992204d6bdb8787024d76
https://github.com/python/cpython/commit/ad4d5ba32af4d80b0dfa2ba9d8203bfb219e60a5
https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48
https://github.com/python/cpython/commit/ceac1efc66516ac387eef2c9a0ce671895b44f03
https://github.com/python/cpython/issues/143930
https://github.com/python/cpython/pull/143931
https://mail.python.org/archives/list/security-announce@python.org/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS/
http://www.openwall.com/lists/oss-security/2026/03/20/1