CVE-2026-0864

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.
CVSS

No CVSS.

Configurations

No configuration.

History

24 Jun 2026, 14:17

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/0adb386f6e68eb2e73d32e19f235d012df009528 -
  • () https://github.com/python/cpython/commit/71f2e02a52d47417a6fd69f456346cd8aa7aca98 -
  • () https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8 -

23 Jun 2026, 19:17

Type Values Removed Values Added
CWE CWE-74

23 Jun 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 18:17

Updated : 2026-07-23 20:17


NVD link : CVE-2026-0864

Mitre link : CVE-2026-0864

CVE.ORG link : CVE-2026-0864


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')