CVE-2026-4519
Severity CVSS v4.0:
HIGH
Type:
CWE-20
Input Validation
Publication date:
20/03/2026
Last modified:
16/04/2026
Description
The webbrowser.open() API would accept leading dashes in the URL which <br />
could be handled as command line options for certain web browsers. New <br />
behavior rejects leading dashes. Users are recommended to sanitize URLs <br />
prior to passing to webbrowser.open().
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
3.30
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | 3.13.13 (excluding) | |
| cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | 3.14.0 (including) | 3.14.4 (excluding) |
| cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:* | ||
| cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:* | ||
| cpe:2.3:a:python:python:3.15.0:alpha3:*:*:*:*:*:* | ||
| cpe:2.3:a:python:python:3.15.0:alpha4:*:*:*:*:*:* | ||
| cpe:2.3:a:python:python:3.15.0:alpha5:*:*:*:*:*:* | ||
| cpe:2.3:a:python:python:3.15.0:alpha6:*:*:*:*:*:* | ||
| cpe:2.3:a:python:python:3.15.0:alpha7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/python/cpython/commit/3681d47a440865aead912a054d4599087b4270dd
- https://github.com/python/cpython/commit/43fe06b96f6a6cf5cfd5bdab20b8649374956866
- https://github.com/python/cpython/commit/591ed890270c5697b013bf637029fb3e6cd2d73e
- https://github.com/python/cpython/commit/594b5a05dc9913880ac92eded440defbf32a28d1
- https://github.com/python/cpython/commit/82a24a4442312bdcfc4c799885e8b3e00990f02b
- https://github.com/python/cpython/commit/89bfb8e5ed3c7caa241028f1a4eac5f6275a46a4
- https://github.com/python/cpython/commit/9669a912a0e329c094e992204d6bdb8787024d76
- https://github.com/python/cpython/commit/96fc5048605863c7b6fd6289643feb0e97edd96c
- https://github.com/python/cpython/commit/ad4d5ba32af4d80b0dfa2ba9d8203bfb219e60a5
- https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48
- https://github.com/python/cpython/commit/cc023511238ad93ecc8796157c6f9139a2bb2932
- https://github.com/python/cpython/commit/ceac1efc66516ac387eef2c9a0ce671895b44f03
- https://github.com/python/cpython/issues/143930
- https://github.com/python/cpython/pull/143931
- https://mail.python.org/archives/list/security-announce@python.org/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS/
- http://www.openwall.com/lists/oss-security/2026/03/20/1



