CVE-2026-0864

Summary

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

Affected Software

VendorProductVersion RangeStatus
Python Software FoundationCPython0 < 3.10.21affected
Python Software FoundationCPython3.11.0 < 3.11.16affected
Python Software FoundationCPython3.12.0 < 3.12.14affected
Python Software FoundationCPython3.13.0 < 3.13.15affected
Python Software FoundationCPython3.14.0 < 3.14.7affected
Python Software FoundationCPython3.15.0a1 < 3.15.0b4affected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References