CLSA-2026-1777457441

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2026-1777457441.json
JSON Data
https://api.test.osv.dev/v1/vulns/CLSA-2026-1777457441
Upstream
Published
2026-05-02T00:58:50Z
Modified
2026-05-27T11:18:21.466546126Z
Summary
python: Fix of 2 CVEs
Details
  • CVE-2026-4519: reject webbrowser.open() URLs with a leading dash to prevent CLI option injection into the spawned browser process
  • CVE-2026-4786: validate URLs after %action substitution and swap the substitution order in UnixBrowser.open() to close a bypass of the CVE-2026-4519 dash-prefix check
References

Affected packages

TuxCare:CentOS:6
python

Package

Name
python
Purl
pkg:rpm/tuxcare/python?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.6-70.el6.tuxcare.els20

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2026-1777457441.json"
python-devel

Package

Name
python-devel
Purl
pkg:rpm/tuxcare/python-devel?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.6-70.el6.tuxcare.els20

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2026-1777457441.json"
python-libs

Package

Name
python-libs
Purl
pkg:rpm/tuxcare/python-libs?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.6-70.el6.tuxcare.els20

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2026-1777457441.json"
python-test

Package

Name
python-test
Purl
pkg:rpm/tuxcare/python-test?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.6-70.el6.tuxcare.els20

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2026-1777457441.json"
python-tools

Package

Name
python-tools
Purl
pkg:rpm/tuxcare/python-tools?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.6-70.el6.tuxcare.els20

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2026-1777457441.json"
tkinter

Package

Name
tkinter
Purl
pkg:rpm/tuxcare/tkinter?distro=centos-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.6-70.el6.tuxcare.els20

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos6els/CLSA-2026-1777457441.json"