Skip to content

CVE-2026-4519 on CTRL-OS 26.05

Aliases: CVE-2026-4519

Packages: python315

Status: Blocked, Resolved

Advisory Information

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open().

Updates

2026-07-31 23:36 CEST

Metadata changes:

  • Status for package python315: “Resolved

(Amended on: 2026-07-31 23:37 CEST)

2026-07-31 23:36 CEST

Metadata changes:

  • Status for package python314: “Resolved

(Amended on: 2026-07-31 23:37 CEST)

2026-07-31 23:36 CEST

Metadata changes:

  • Status for package python313: “Resolved

(Amended on: 2026-07-31 23:37 CEST)

2026-07-31 23:36 CEST

Metadata changes:

  • Status for package python312: “Blocked

Comment:

No update tagged upstream.

(Amended on: 2026-07-31 23:39 CEST)

2026-07-31 23:36 CEST

Metadata changes:

  • Status for package python311: “Blocked

Comment:

No update tagged upstream.

(Amended on: 2026-07-31 23:38 CEST)

2026-07-31 23:34 CEST

Metadata changes:

  • Status for package python311: “Plausible
  • Status for package python312: “Plausible
  • Status for package python313: “Plausible
  • Status for package python314: “Plausible
  • Status for package python315: “Plausible

(Amended on: 2026-07-31 23:37 CEST)

2026-07-31 01:08 CEST

Metadata changes:

  • Status for package python311: “New
  • Status for package python312: “New
  • Status for package python313: “New
  • Status for package python314: “New
  • Status for package python315: “New

(Amended on: 2026-07-31 23:36 CEST)