EIP-2026-116112
PRE-CVEPython 3.3 < 3.5 - 'product_setstate()' Out-of-Bounds Read
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-116112. PoCs published by John Leitch.
AI-analyzed exploit summary This is a detailed technical analysis of CVE-2026-158766, an out-of-bounds read vulnerability in Python 3.3-3.5's `product_setstate()` function. It includes root cause analysis, code snippets, and a proof-of-concept script demonstrating the issue.
Description
Python 3.3 < 3.5 - 'product_setstate()' Out-of-Bounds Read
Exploits (1)
exploitdb
WRITEUP
by John Leitch · textdoswindows
https://www.exploit-db.com/exploits/38618
This is a detailed technical analysis of CVE-2026-158766, an out-of-bounds read vulnerability in Python 3.3-3.5's `product_setstate()` function. It includes root cause analysis, code snippets, and a proof-of-concept script demonstrating the issue.
Classification
Writeup 100%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target:
Python 3.3 - 3.5
No auth needed
Prerequisites:
Python 3.3-3.5 environment
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026