When using the "configparser" module to write configuration files
containing multi-line text values with carriage return characters (\r) the
resulting file could be injected with unexpected keys and values if the
attacker controls the written value.
CVSS
No CVSS.
References
Configurations
No configuration.
History
24 Jun 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
23 Jun 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-74 |
23 Jun 2026, 18:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-23 18:17
Updated : 2026-07-23 20:17
NVD link : CVE-2026-0864
Mitre link : CVE-2026-0864
CVE.ORG link : CVE-2026-0864
JSON object : View
Products Affected
No product.
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
