When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.
"https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2026-0864.json"