CVE-2026-4786
high
CVSS v3
โ
CVSS v4 NEW
7.0
VIR risk
8.0
Description
Important: python3.11 security update
Predictions
Exploit likelihood
20%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rhel | 9 | fixed | |
| debian | bookworm | fixed | 0 |
| debian | bullseye | fixed | 0 |
| debian | forky | fixed | 0 |
| debian | sid | fixed | 0 |
| debian | trixie | fixed | 0 |
| sles | affected | | |
| rocky | 9 | fixed | |
| almalinux | 9 | fixed | python3.11-3.11.13-9.el9_8.aarch64.rpm |
References
- https://access.redhat.com/errata/RHSA-2026:10745
- https://access.redhat.com/errata/RHSA-2026:10774
- https://access.redhat.com/errata/RHSA-2026:10949
- https://access.redhat.com/errata/RHSA-2026:19175
- https://access.redhat.com/errata/RHSA-2026:19176
- https://access.redhat.com/errata/RHSA-2026:19177
- https://access.redhat.com/errata/RHSA-2026:19216
- https://github.com/python/cpython/commit/28b4ad38067bbdad34edfcd03ad2de5f06387e53
- https://github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca
- https://github.com/python/cpython/commit/d22922c8a7958353689dc4763dd72da2dea03fff
- https://github.com/python/cpython/commit/d6d68494be70bdbda20f89f83801ba52ec37daa4
- https://github.com/python/cpython/commit/f4654824ae0850ac87227fb270f9057477946769
- https://github.com/python/cpython/issues/148169
- https://github.com/python/cpython/pull/148170
- https://mail.python.org/archives/list/security-announce@python.org/thread/JQDUNJVB4AQNTJECSUKOBDU3XCJIPSE5/
- https://security-tracker.debian.org/tracker/CVE-2026-4786
- https://www.suse.com/security/cve/CVE-2026-4786.html
- https://access.redhat.com/errata/RHSA-2026:11062
- https://bugzilla.redhat.com/2457932
- https://bugzilla.redhat.com/2458049
- https://errata.almalinux.org/8/ALSA-2026-11062.html
- https://access.redhat.com/errata/RHSA-2026:11077
- https://errata.almalinux.org/8/ALSA-2026-11077.html
- https://errata.almalinux.org/9/ALSA-2026-10949.html
- https://errata.almalinux.org/9/ALSA-2026-10745.html
CWEs
CWE-77
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.