CVE-2026-4786
Python Software Foundation CPython, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
- CVSS
- 7
- EPSS
- 0.29% 21.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.14