Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-3298

30
FAUCET Score

CVE-2026-3298 is a buffer overflow vulnerability in Python's asyncio library affecting the sock_recvfrom_into() method of ProactorEventLoop on Windows systems only. The flaw exists due to missing boundary validation on the data buffer when the nbytes parameter is used, potentially allowing an attacker to write data beyond the allocated buffer size. Non-Windows platforms running asyncio are not affected by this vulnerability. The vulnerability presents a moderate risk profile with a FAUCET Risk Score of 51.0/100, though official CVSS metrics are not yet assigned. The nature of the out-of-bounds write could enable memory corruption attacks, though the actual attack vector complexity and real-world impact remain constrained by the asyncio-specific context and Windows-only scope. This vulnerability is not currently being actively exploited in the wild, as indicated by its absence from the Known Exploited Vulnerabilities catalog and its inactive status on threat tracking lists. The low EPSS score of 0.0005 suggests minimal current exploitation probability. Community and security attention appears limited at this time, with no publicly available exploit code reported.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.11.0, < 3.13.14CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.8HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.37%
Probability of exploitation in next 30 days
EPSS Percentile
30.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 10th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-3298Important

Out-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes

Apr 14, 2026

References

github.com / python/cpython/commit/1274766d3c29007ab77245a72abbf8dce2a9db4d
github.com / python/cpython/commit/27522b7d6e6588f03e61099dd858cd5a9314e2f2
github.com / python/cpython/commit/95633d2aad4721e25e4dfd9f43dfb6e1edcbd741
github.com / python/cpython/issues/148808
github.com / python/cpython/pull/148809
mail.python.org / archives/list/[email protected]/thread/KWTPIQBOOOUNQP7UFSLBI437NJDFLA3F