Linuxsecurity Critical CVE Fixes for Fedora Python Packages Released
Article Content
- •Fedora released updates for python-lsp-black and python-black to address critical CVEs.
- •CVE-2026-31900 and CVE-2026-32274 pose serious risks of privilege escalation.
- •Users must upgrade to the latest package versions to protect their systems.
Fedora has issued important security updates for two Python packages: python-lsp-black and python-black, addressing serious vulnerabilities identified as CVE-2026-31900 and CVE-2026-32274. These vulnerabilities could lead to privilege escalation and system-wide damage if exploited. Users are advised to upgrade to the latest versions—python-lsp-black to 2.0.0-17 and python-black to 26.5.1. The vulnerabilities were published earlier this year, with CVE-2026-31900 having a proof of concept released in April 2026. The updates are available through the dnf package manager, and users are urged to apply them promptly to mitigate risks. Both packages are part of Fedora 44 and are critical for Python development environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora and CVE-2026-31900 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…