Skip to content
Critical Python Vulnerabilities Affect Multiple Ubuntu Versions

Critical Python Vulnerabilities Affect Multiple Ubuntu Versions

First seen 11 Sep 2026, 04:46 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 11, 2026 at 07:17 UTC
  • Critical vulnerabilities in Python affect Ubuntu 14.04 to 24.04 LTS.
  • Attackers can exploit these flaws for denial of service and code injection.
  • Patches are available; immediate updates are recommended.

Multiple vulnerabilities in Python's modules have been identified, affecting Ubuntu 14.04 LTS to 24.04 LTS. Key issues include improper handling of control characters in the http.cookies module (CVE-2026-3644), unbounded recursion in the pyexpat module leading to denial of service (CVE-2026-4224), and incorrect extraction of hard links in the tarfile module (CVE-2026-4360). These vulnerabilities could allow attackers to inject arbitrary content or crash systems, impacting a wide range of users. The vulnerabilities were disclosed on September 10, 2026, and patches are available for affected systems. Security professionals are urged to update their Python installations promptly to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-03-16
CVE-2026-3644 published
Python's http.cookies module vulnerability allows arbitrary content injection.
Ubuntu
2026-03-16
CVE-2026-4224 published
Unbounded recursion in the pyexpat module could lead to denial of service.
Ubuntu
2026-04-22
CVE-2026-6019 published
Python's http.cookies module improperly escapes values, allowing JavaScript injection.
Ubuntu
2026-06-30
CVE-2026-4360 published
Improper handling of hard links in tarfile module could bypass security restrictions.
Ubuntu
2026-07-09
CVE-2026-15308 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-10
Python vulnerabilities disclosed
Multiple vulnerabilities affecting various Python versions were announced, urging immediate updates.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2026-15308 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed