4.1
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Description
When using the "configparser" module to write configuration files
containing multi-line text values with carriage return characters (\r) the
resulting file could be injected with unexpected keys and values if the
attacker controls the written value.
containing multi-line text values with carriage return characters (\r) the
resulting file could be injected with unexpected keys and values if the
attacker controls the written value.
Basic Information
ID
CVE-2026-0864
Source
PSF
Published
Jun 23, 2026 at 17:42
Modified
Jun 23, 2026 at 17:56
Affected Product
Vendor
Python Software Foundation
Product
CPython
Affected Versions
Python Software Foundation CPython 0