CVE-2026-3298 is a buffer overflow vulnerability in Python's asyncio library affecting the sock_recvfrom_into() method of ProactorEventLoop on Windows systems only. The flaw exists due to missing boundary validation on the data buffer when the nbytes parameter is used, potentially allowing an attacker to write data beyond the allocated buffer size. Non-Windows platforms running asyncio are not affected by this vulnerability. The vulnerability presents a moderate risk profile with a FAUCET Risk Score of 51.0/100, though official CVSS metrics are not yet assigned. The nature of the out-of-bounds write could enable memory corruption attacks, though the actual attack vector complexity and real-world impact remain constrained by the asyncio-specific context and Windows-only scope. This vulnerability is not currently being actively exploited in the wild, as indicated by its absence from the Known Exploited Vulnerabilities catalog and its inactive status on threat tracking lists. The low EPSS score of 0.0005 suggests minimal current exploitation probability. Community and security attention appears limited at this time, with no publicly available exploit code reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.11.0, < 3.13.14CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.