Skip to content
Fedora 42 Python 3.15 Vulnerability 2026 Risk of Arbitrary Code Execution

Fedora 42 Python 3.15 Vulnerability 2026 Risk of Arbitrary Code Execution

Linuxsecurity LinuxSecurity Advisories May 23, 2026

[ 1 ] Bug #2457945 - CVE-2026-1502 python3.15: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all] [ 2 ] Bug #2458017 - CVE-2026-6100 python3.15: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules [fedora-all] [ 3 ] Bug #2458225 - CVE-2026-4786 python3.15: Python: Arbitrary code execution via command injection in webbrowser.open() API [fedora-all] [ 4 ] Bug #2458489 - CVE-2026-5713 python3.15: Python: Information disclosure and arbitrary code execution via remote debugging with a malicious process. [fedora-all] [ 5 ] Bug #2461289 - CVE-2026-3219 python3.15: pip: Incorrect file installation due to improper archive handling [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-e7dc1a8950' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.