Opened 6 weeks ago
Closed 6 days ago
#6007 closed enhancement (fixed)
Python-3.14.8 with several security fixes.
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | highest | Milestone: | 13.2 |
| Component: | Book | Version: | git |
| Severity: | critical | Keywords: | |
| Cc: |
Description
Recent security updates:
Subject: [Security-announce][CVE-2026-17084] StringPrep algorithm considered Unicode codepoint attributes outside Unicode 3.2.0 Date: Tue, 18 Aug 2026 13:55:39 +0000 From: Seth Larson <seth@...hon.org> Reply-To: security-sig@...hon.org To: security-announce@...hon.org There is a MEDIUM severity vulnerability affecting CPython. The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0. Please see the linked CVE ID for the latest information on affected versions: * https://www.cve.org/CVERecord?id=CVE-2026-17084 * https://github.com/python/cpython/pull/155293
Backport for the 3.14 branch: https://github.com/python/cpython/pull/156020
This is still open.
Subject: [Security-announce][CVE-2026-15806] urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over another scheme Date: Tue, 18 Aug 2026 15:38:30 +0000 From: Kirill Podoprigora via Security-announce <security-announce@...hon.org> Reply-To: security-sig@...hon.org To: security-announce@...hon.org CC: Kirill Podoprigora <kirill.bast@...il.com> There is a MEDIUM severity vulnerability affecting CPython. The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication. Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs. Please see the linked CVE ID for the latest information on affected versions: - https://www.cve.org/CVERecord?id=CVE-2026-15806 - https://github.com/python/cpython/pull/155696
Backport for the 3.14 branch: https://github.com/python/cpython/pull/155969
Merged.
Subject: [Security-announce][CVE-2026-19672] tarfile extraction filter bypass allows creation of directories outside the destination Date: Wed, 19 Aug 2026 14:56:06 +0100 From: Stan Ulbrych via Security-announce <security-announce@...hon.org> Reply-To: security-sig@...hon.org To: security-announce@...hon.org CC: Stan Ulbrych <stanulbrych@...il.com> There is a MEDIUM severity vulnerability affecting CPython. The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given. Only empty directories are created outside the destination. Member contents are still extracted inside it. To return to the destination the member's name must contain the destination directory's own final component, so extraction into a secure randomised directory is not affected. This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created. Please see the linked CVE ID for the latest information on affected versions: * https://www.cve.org/CVERecord?id=CVE-2026-19672 * https://github.com/python/cpython/pull/156000
Backport for the 3.14 branch: https://github.com/python/cpython/pull/156041
Merged.
Change History (10)
comment:1 by , 8 days ago
| Priority: | normal → highest |
|---|---|
| Severity: | normal → critical |
| Summary: | Python security fixes: CVE-2026-17084,15806,19672 → Python security fixes: CVE-2026-17084,15806,19672,15310,87910,12345,19553,19445 |
comment:2 by , 8 days ago
| Summary: | Python security fixes: CVE-2026-17084,15806,19672,15310,87910,12345,19553,19445 → Python security fixes. Waiting for next version of Python due October 1st. |
|---|
The next version will be 3.15.
comment:3 by , 7 days ago
| Summary: | Python security fixes. Waiting for next version of Python due October 1st. → Python-3.14.8 with several security fixes. |
|---|
The changes are relatively extensive: https://docs.python.org/release/3.14.8/whatsnew/changelog.html
follow-up: 5 comment:4 by , 7 days ago
I an VERY surprised. Python-3.14.8 FTBFS without the openssl_4-1.patch.
follow-up: 6 comment:5 by , 7 days ago
Replying to Bruce Dubbs:
I an VERY surprised. Python-3.14.8 FTBFS without the openssl_4-1.patch.
When I build this after a full LFS build it doesn't bomb for me?
follow-up: 7 comment:6 by , 7 days ago
Replying to Joe Locash:
Replying to Bruce Dubbs:
I an VERY surprised. Python-3.14.8 FTBFS without the openssl_4-1.patch.
When I build this after a full LFS build it doesn't bomb for me?
You built it without the patch?
comment:7 by , 7 days ago
Replying to Bruce Dubbs:
Replying to Joe Locash:
Replying to Bruce Dubbs:
I an VERY surprised. Python-3.14.8 FTBFS without the openssl_4-1.patch.
When I build this after a full LFS build it doesn't bomb for me?
You built it without the patch?
Yes
comment:8 by , 7 days ago
I tried building Python-3.14.8 in a full system, but ran into a couple of problems. I tried without the patch. This is from my log:
checking for stdlib extension module _ssl... yes ... [ERROR] _ssl failed to import: /build/python/Python-3.14.8/build/lib.linux-x86_64-3.14/_ssl.cpython-314-x86_64-linux-gnu.so: undefined symbol: TLSv1_method Following modules built successfully but were removed because they could not be imported: _ssl Could not build the ssl module! Python requires a OpenSSL 1.1.1 or newer
I got that twice.
In the tests:
0:00:08 load avg: 4.31 [256/492/1] test_ssl skipped
test_ssl skipped -- No module named '_ssl'
...
1 test failed:
test_importlib
Then during the install:
/usr/bin/install -c -m 755 Modules/_ssl.cpython-314-x86_64-linux-gnu.so /usr/lib/python3.14/lib-dynload/_ssl.cpython-314-x86_64-linux-gnu.so install: cannot stat 'Modules/_ssl.cpython-314-x86_64-linux-gnu.so': No such file or directory make: *** [Makefile:2569: sharedinstall] Error 1
The base executable, python3, was installed, but the process stopped at that point.
comment:9 by , 6 days ago
| Owner: | changed from to |
|---|
Updated at commit e640dd0f6. Leaving open for security advisory.
comment:10 by , 6 days ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.1-044 has been issued.

Two more vulnerabilites were announced today, one is high and the other is critical. Also included are the minor ones previously announced.
3.14 fix: https://github.com/python/cpython/commit/31980e84b9a708424a0a1dfecde3fc991e313f89
3.14 backport: https://github.com/python/cpython/pull/157307
3.14 backport: https://github.com/python/cpython/pull/158430 (open)
3.14 backport: https://github.com/python/cpython/pull/158509
3.14 backport: https://github.com/python/cpython/pull/158515