CVE-2026-0864

Aliases:UBUNTU-CVE-2026-0864DEBIAN-CVE-2026-0864ALPINE-CVE-2026-0864CGA-35qc-6mjj-c2qpCGA-3797-65xv-g227CGA-3c54-5jpq-3544CGA-3hwv-c528-82x9CGA-4rwv-hcmp-4f74CGA-552f-hg2q-367mCGA-7hpc-7m58-8xwhCGA-mcc6-wwhc-pmfhCGA-xjqj-qh8m-vpc4CGA-xx25-7g6h-c3pm
Analyzed
Published: 23 Jun 2026, 17:42
Last modified:13 Aug 2026, 00:29

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.13% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jun 2026, 17:42
Published
Vulnerability first disclosed
13 Aug 2026, 00:29
Last Modified
Vulnerability information updated

Description

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

CVSS Metrics

  • v4.0MEDIUMScore: 4.1CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 4.1CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.13% Percentile: 3%

Techniques & Countermeasures

  • CWE-74Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

    The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Affected Systems

  • alpinepython3

    < 3.12.14-r0 | < 3.12.14-r0 | < 3.12.14-r0 | < 3.14.7-r0

  • chainguardpython-3.10

    < 3.10.20-r10

  • chainguardpython-3.11

    < 3.11.15-r8

  • chainguardpython-3.12

    < 3.12.13-r10

  • chainguardpython-3.13

    < 3.13.14-r2

  • chainguardpython-3.14

    < 3.14.6-r3

  • wolfipython-3.10

    < 3.10.20-r10

  • wolfipython-3.11

    < 3.11.15-r8

  • wolfipython-3.12

    < 3.12.13-r10

  • wolfipython-3.13

    < 3.13.14-r2

  • wolfipython-3.14

    < 3.14.6-r3

  • debianpypy3

    all | all | all | all

  • debianpython2.7

    all

  • debianpython3.11

    all

  • debianpython3.13

    all | all | < 3.13.5-2+deb13u5 | < 3.13.15-1

  • debianpython3.14

    all | < 3.14.7-1

  • debianpython3.9

    all

  • ubuntupython2.7

    all

  • ubuntupython3.10

    all

  • ubuntupython3.11

    all | all

  • ubuntupython3.12

    all

  • ubuntupython3.13

    all

  • ubuntupython3.14

    all | all

  • ubuntupython3.4

    all

  • ubuntupython3.5

    all

  • ubuntupython3.6

    all

  • ubuntupython3.7

    all

  • ubuntupython3.8

    all

  • ubuntupython3.9

    all

  • python software foundationcpython

    < 3.15.0 | < 3.13.15 | < 3.10.21 | ≥ 3.11.0, < 3.11.16 | ≥ 3.12.0, < 3.12.14 | ≥ 3.13.0, < 3.13.15 | ≥ 3.14.0, < 3.14.7 | ≥ 3.15.0a1, < 3.15.0b4

  • pythonpython

    < 3.10.21 | ≥ 3.11.0, < 3.11.16 | ≥ 3.12.0, < 3.12.14 | ≥ 3.13.0, < 3.13.15 | ≥ 3.14.0, < 3.14.7 | 3.15.0:alpha1 | 3.15.0:alpha2 | 3.15.0:alpha3 | 3.15.0:alpha4 | 3.15.0:alpha5 | 3.15.0:alpha6 | 3.15.0:alpha7 | 3.15.0:alpha8 | 3.15.0:beta1 | 3.15.0:beta2 | 3.15.0:beta3

References (17)