Back Linuxsecurity Fedora python3.13 Important Security Fixes Advisory 2026
[ 1 ] Bug #2457943 - CVE-2026-1502 python3.13: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all] [ 2 ] Bug #2458015 - CVE-2026-6100 python3.13: Python: Arbitrary code execution or information disclosure via use-after-free in decompression modules [fedora-all] [ 3 ] Bug #2458223 - CVE-2026-4786 python3.13: Python: Arbitrary code execution via command injection in webbrowser.open() API [fedora-all] [ 4 ] Bug #2484194 - CVE-2026-7210 python3.13: Python/Expat: Denial of Service via crafted XML document [fedora-all] [ 5 ] Bug #2484559 - CVE-2026-3276 python3.13: Python unicodedata: Denial of Service due to excessive CPU consumption [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dfc9182263' at the command line. For more information, refer to the dnf documentation available at
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
