CVE-2026-0864

MEDIUM

Configuration Injection via Carriage Return (\r) in write() method

Title source: cna
STIX 2.1

Description

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

Scores

CVSS v4 4.1
EPSS 0.0013
EPSS Percentile 2.8%
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-74
Status published
Products (2)
Python Software Foundation/CPython < 3.15.0
Python Software Foundation/CPython < 3.15.0b4
Published Jun 23, 2026
Tracked Since Jun 24, 2026