Critical CVE Fixes for Fedora Python Packages Released

Critical CVE Fixes for Fedora Python Packages Released

First seen 24 Jul 2026, 10:07 UTC Linuxsecurity 80% similarity 72.0

Article Content

Browse articles
ThreatCluster

Fedora has issued important security updates for two Python packages: python-lsp-black and python-black, addressing serious vulnerabilities identified as CVE-2026-31900 and CVE-2026-32274. These vulnerabilities could lead to privilege escalation and system-wide damage if exploited. Users are advised to upgrade to the latest versions—python-lsp-black to 2.0.0-17 and python-black to 26.5.1. The vulnerabilities were published earlier this year, with CVE-2026-31900 having a proof of concept released in April 2026. The updates are available through the dnf package manager, and users are urged to apply them promptly to mitigate risks. Both packages are part of Fedora 44 and are critical for Python development environments.

Key Points: • Fedora released updates for python-lsp-black and python-black to address critical CVEs. • CVE-2026-31900 and CVE-2026-32274 pose serious risks of privilege escalation. • Users must upgrade to the latest package versions to protect their systems.

ThreatCluster AI

Timeline

2026-03-11
CVE-2026-31900 published
CVE-2026-31900 was published, detailing a serious vulnerability affecting Python packages.
Linuxsecurity
2026-03-12
CVE-2026-32274 published
CVE-2026-32274 was published, highlighting another critical vulnerability in Python packages.
Linuxsecurity
2026-04-02
First public PoC for CVE-2026-31900
A proof of concept for CVE-2026-31900 was released, demonstrating potential exploitation methods.
Linuxsecurity
2026-07-14
Updates for python-lsp-black and python-black released
Fedora released updates for both packages to address the identified vulnerabilities.
Linuxsecurity
2026-07-24
Current advisory published
Fedora issued a security advisory urging users to upgrade to the latest versions to mitigate risks.
Linuxsecurity

Community

Browse all →