Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91260.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-91260
Upstream
Published
2026-06-23T18:17:41Z
Modified
2026-09-05T05:27:51Z
Summary
CVE-2026-0864 affecting package python3 for versions less than 3.12.9-14
Details

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

References

Affected packages

Azure Linux:3 / python3

Package

Name
python3
Purl
pkg:rpm/azure-linux/python3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.12.9-14

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91260.json"