Back Linuxsecurity Fedora 42 python3.9 Critical Command Injection Fix FEDORA-2026
Python 3.9 package for developers. This package exists to allow developers to test their code against an older version of Python. This is not a full Python stack and if you wish to run your applications with Python 3.9, see other distributions that support it, such as CentOS or RHEL or older Fedora releases. Update Information : Security fixes for CVE-2026-1299, CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367
Python 3.9 package for developers.
This package exists to allow developers to test their code against an older
version of Python. This is not a full Python stack and if you wish to run
your applications with Python 3.9, see other distributions
that support it, such as CentOS or RHEL or older Fedora releases.
Security fixes for CVE-2026-1299, CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367
* Tue Feb 10 2026 Tom\u0161 Hrn\u010diar - 3.9.25-6 - Security fix for CVE-2026-1299 * Mon Feb 9 2026 Tom\u0161 Hrn\u010diar - 3.9.25-5 - Security fixes for CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367 * Sat Jan 17 2026 Fedora Release Engineering - 3.9.25-4 - Rebuilt for
* Tue Feb 10 2026 Tom\u0161 Hrn\u010diar - 3.9.25-6 - Security fix for CVE-2026-1299 * Mon Feb 9 2026 Tom\u0161 Hrn\u010diar - 3.9.25-5 - Security fixes for CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367 * Sat Jan 17 2026 Fedora Release Engineering - 3.9.25-4 - Rebuilt for
[ 1 ] Bug #2431622 - CVE-2025-15366 python3.9: IMAP command injection in user-controlled commands [fedora-42] [ 2 ] Bug #2431646 - CVE-2025-15367 python3.9: POP3 command injection in user-controlled commands [fedora-42] [ 3 ] Bug #2431810 - CVE-2026-0865 python3.9: wsgiref.headers.Headers allows header newline injection in Python [fedora-42] [ 4 ] Bug #2433822 - CVE-2026-1299 python3.9: email header injection due to unquoted newlines [fedora-42]
[ 1 ] Bug #2431622 - CVE-2025-15366 python3.9: IMAP command injection in user-controlled commands [fedora-42] [ 2 ] Bug #2431646 - CVE-2025-15367 python3.9: POP3 command injection in user-controlled commands [fedora-42] [ 3 ] Bug #2431810 - CVE-2026-0865 python3.9: wsgiref.headers.Headers allows header newline injection in Python [fedora-42] [ 4 ] Bug #2433822 - CVE-2026-1299 python3.9: email header injection due to unquoted newlines [fedora-42]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-cad5404d98' at the command line. For more information, refer to the dnf documentation available at
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-cad5404d98' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
