NVD Description
Note: Versions mentioned in the description apply only to the upstream python3 package and not the python3 package as distributed by RHEL.
See How to fix? for RHEL:9 relevant fixed versions and status.
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Remediation
Upgrade RHEL:9 python3 to version 0:3.9.25-3.el9_7.3 or higher.
This issue was patched in RHSA-2026:10949.
References
NVD Description
Note: Versions mentioned in the description apply only to the upstream
python3package and not thepython3package as distributed byRHEL.See
How to fix?forRHEL:9relevant fixed versions and status.Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Remediation
Upgrade
RHEL:9python3to version 0:3.9.25-3.el9_7.3 or higher.This issue was patched in
RHSA-2026:10949.References
webbrowser:%actionsubstitution can bypass the dash-prefix check python/cpython#148169%actionsubstitution bypass of dash-prefix check python/cpython#148170