Skip to content

CVE-2026-0864 on CTRL-OS 26.05

Aliases: CVE-2026-0864

Packages: python3

Status: Plausible

Advisory Information

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

Updates

2026-07-07 18:39 CEST

Metadata changes:

  • Status for package python3: “Plausible

(Amended on: 2026-07-07 18:41 CEST)

2026-07-07 18:34 CEST

Metadata changes:

  • Status for package python3: “New