Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 13 Apr 2026 23:04:53 +0000
From:      bugzilla-noreply@freebsd.org
To:        python@FreeBSD.org
Subject:   [Bug 294496] lang/python*: CVE-2026-4786: webbrowser.open() command injection mitigation for CVE-2026-4519 was incomplete
Message-ID:  <bug-294496-21822-RsvYuIKyCM@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-294496-21822@https.bugs.freebsd.org/bugzilla/>

index | next in thread | previous in thread | raw e-mail

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=294496

Matthias Andree <mandree@FreeBSD.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
 Attachment #269741|                            |maintainer-approval+
              Flags|                            |

--- Comment #3 from Matthias Andree <mandree@FreeBSD.org> ---
Created attachment 269741
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=269741&action=edit
python 3.14.4_1 -> _2 update to fix CVE-2026-4786, Incomplete mitigation of
CVE-2026-4519,     %action expansion for command injection to webbrowser.open()

-- 
You are receiving this mail because:
You are on the CC list for the bug.

home | help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-294496-21822-RsvYuIKyCM>