[CVE-2026-0864] Configparser newline injection in write() method
June 23, 2026
5:40 p.m.
There is a MEDIUM severity vulnerability affecting CPython.
When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.
Please see the linked CVE ID for the latest information on affected versions:
56
Age (days ago)
56
Last active (days ago)
0 comments
1 participants
participants (1)
-
Seth Larson