Skip to content

CVE-2026-3446 on CTRL-OS 26.05

Aliases: CVE-2026-3446

Packages: python313

Status: Plausible, Resolved

Advisory Information

When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "validate=True" to enable stricter processing of base64 data.

Updates

2026-07-23 16:20 CEST

Metadata changes:

  • Status for package python313: “Resolved” (fff38d56fb8e15a140da141149c596766b838d0b)

2026-07-23 16:20 CEST

Metadata changes:

  • Status for package python314: “Resolved” (b907b8ba5e335b35aed7b8b2d2f2058d8f10e055)

2026-07-23 16:20 CEST

Metadata changes:

  • Status for package python315: “Resolved” (efbecb049efee52f0b276729d22033a6e2c7265b)

2026-07-23 16:19 CEST

Metadata changes:

  • Status for package python311: “Plausible
  • Status for package python312: “Plausible
  • Status for package python313: “Plausible
  • Status for package python314: “Plausible
  • Status for package python315: “Plausible

2026-06-01 17:44 CEST

Metadata changes:

  • Status for package python311: “New
  • Status for package python312: “New
  • Status for package python313: “New
  • Status for package python314: “New
  • Status for package python315: “New

(Amended on: 2026-06-01 17:45 CEST)