CVE-2026-4519 on CTRL-OS 26.05
Aliases: CVE-2026-4519
Packages: python315
Status: Blocked, Resolved
Advisory Information
The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().
Updates
2026-07-31 23:36 CEST
Metadata changes:
- Status for package
python315: “Resolved”
(Amended on: 2026-07-31 23:37 CEST)
2026-07-31 23:36 CEST
Metadata changes:
- Status for package
python314: “Resolved”
(Amended on: 2026-07-31 23:37 CEST)
2026-07-31 23:36 CEST
Metadata changes:
- Status for package
python313: “Resolved”
(Amended on: 2026-07-31 23:37 CEST)
2026-07-31 23:36 CEST
Metadata changes:
- Status for package
python312: “Blocked”
Comment:
No update tagged upstream.
(Amended on: 2026-07-31 23:39 CEST)
2026-07-31 23:36 CEST
Metadata changes:
- Status for package
python311: “Blocked”
Comment:
No update tagged upstream.
(Amended on: 2026-07-31 23:38 CEST)
2026-07-31 23:34 CEST
Metadata changes:
- Status for package
python311: “Plausible” - Status for package
python312: “Plausible” - Status for package
python313: “Plausible” - Status for package
python314: “Plausible” - Status for package
python315: “Plausible”
(Amended on: 2026-07-31 23:37 CEST)
2026-07-31 01:08 CEST
Metadata changes:
- Status for package
python311: “New” - Status for package
python312: “New” - Status for package
python313: “New” - Status for package
python314: “New” - Status for package
python315: “New”
(Amended on: 2026-07-31 23:36 CEST)