Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4519

22
FAUCET Score

CVE-2026-4519 describes a vulnerability in the `webbrowser.open()` API, part of Python's standard library, where it improperly accepts URLs containing leading dashes. This flaw allows certain web browsers to interpret these dashes as command-line options, potentially leading to high confidentiality and integrity impacts on a user's system. Rated High with a CVSSv4 score of 7.0, exploitation requires local access and user interaction, though the attack complexity is low. Currently, there is no evidence of active exploitation, nor are public exploit modules available, and community attention remains minimal. Users are advised to sanitize URLs before passing them to `webbrowser.open()` to mitigate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 3.13.13CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.14.0, < 3.14.4CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
< 3.13.13CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
3.15.0CPE matchmatch criteria
cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:*
3.15.0CPE matchmatch criteria
cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.0HIGH

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
23.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 38th percentile among its peer group of 577 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: 21100-17084Fixed in: 3.12.9-10
microsoftpatch availablevia msrc
Product: 20962-17084Fixed in: 3.12.9-10
microsoftpatch availablevia msrc
Product: 20937-17086Fixed in: 3.9.19-20
microsoftpatch availablevia msrc
Product: azl3 python3 3.12.9-10 on Azure Linux 3.0Fixed in: 3.12.9-10
microsoftpatch availablevia msrc
Product: cbl2 python3 3.9.19-19 on CBL Mariner 2.0Fixed in: 3.9.19-20
microsoftpatch availablevia msrc
Product: azl3 python3 3.12.9-9 on Azure Linux 3.0Fixed in: 3.12.9-10
ubuntupatch availablevia ubuntu_usn
Product: python3.10 (jammy)Fixed in: 3.10.12-1~22.04.16
ubuntupatch availablevia ubuntu_usn
Product: python3.12 (noble)Fixed in: 3.12.3-1ubuntu0.15
ubuntupatch availablevia ubuntu_usn
Product: python3.14 (resolute)Fixed in: 3.14.4-1ubuntu0.1

Vendor Advisories (2)

ubuntuUSN-8509-1

Python vulnerabilities

Jul 6, 2026
microsoft2026-Mar/CVE-2026-4519Important

webbrowser.open() allows leading dashes in URLs

Mar 10, 2026

References

access.redhat.com / errata/RHSA-2026:10065
access.redhat.com / errata/RHSA-2026:10101
access.redhat.com / errata/RHSA-2026:10102
access.redhat.com / errata/RHSA-2026:10111
access.redhat.com / errata/RHSA-2026:10140
access.redhat.com / errata/RHSA-2026:10141
access.redhat.com / errata/RHSA-2026:13812
access.redhat.com / errata/RHSA-2026:16008
access.redhat.com / errata/RHSA-2026:16009
access.redhat.com / errata/RHSA-2026:16030
access.redhat.com / errata/RHSA-2026:16174
access.redhat.com / errata/RHSA-2026:19019
access.redhat.com / errata/RHSA-2026:19064
access.redhat.com / errata/RHSA-2026:19175
access.redhat.com / errata/RHSA-2026:19176
access.redhat.com / errata/RHSA-2026:19177
access.redhat.com / errata/RHSA-2026:19216
access.redhat.com / errata/RHSA-2026:19724
access.redhat.com / errata/RHSA-2026:19725
access.redhat.com / errata/RHSA-2026:21275
access.redhat.com / errata/RHSA-2026:25096
access.redhat.com / errata/RHSA-2026:6016
access.redhat.com / errata/RHSA-2026:6035
access.redhat.com / errata/RHSA-2026:6256
access.redhat.com / errata/RHSA-2026:6281
access.redhat.com / errata/RHSA-2026:6283
access.redhat.com / errata/RHSA-2026:6285
access.redhat.com / errata/RHSA-2026:6286
access.redhat.com / errata/RHSA-2026:6473
access.redhat.com / errata/RHSA-2026:6766
access.redhat.com / errata/RHSA-2026:7010
access.redhat.com / errata/RHSA-2026:7244
access.redhat.com / errata/RHSA-2026:7329
access.redhat.com / errata/RHSA-2026:7335
access.redhat.com / errata/RHSA-2026:7443
access.redhat.com / errata/RHSA-2026:7661
access.redhat.com / errata/RHSA-2026:8746
access.redhat.com / errata/RHSA-2026:8747
access.redhat.com / errata/RHSA-2026:8748
access.redhat.com / errata/RHSA-2026:9042
access.redhat.com / errata/RHSA-2026:9260
access.redhat.com / errata/RHSA-2026:9261
access.redhat.com / errata/RHSA-2026:9262
access.redhat.com / errata/RHSA-2026:9289
access.redhat.com / errata/RHSA-2026:9354
access.redhat.com / errata/RHSA-2026:9386
access.redhat.com / errata/RHSA-2026:9387
access.redhat.com / errata/RHSA-2026:9591
access.redhat.com / errata/RHSA-2026:9614
access.redhat.com / errata/RHSA-2026:9621
access.redhat.com / errata/RHSA-2026:9705
access.redhat.com / errata/RHSA-2026:9745
access.redhat.com / security/cve/CVE-2026-4519
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-4519.json
openwall.com / lists/oss-security/2026/03/20/1
Mailing ListThird Party Advisory
github.com / python/cpython/commit/3681d47a440865aead912a054d4599087b4270dd
Patch
github.com / python/cpython/commit/43fe06b96f6a6cf5cfd5bdab20b8649374956866
Patch
github.com / python/cpython/commit/591ed890270c5697b013bf637029fb3e6cd2d73e
Patch
github.com / python/cpython/commit/594b5a05dc9913880ac92eded440defbf32a28d1
Patch
github.com / python/cpython/commit/82a24a4442312bdcfc4c799885e8b3e00990f02b
Patch
github.com / python/cpython/commit/89bfb8e5ed3c7caa241028f1a4eac5f6275a46a4
Patch
github.com / python/cpython/commit/9669a912a0e329c094e992204d6bdb8787024d76
Patch
github.com / python/cpython/commit/96fc5048605863c7b6fd6289643feb0e97edd96c
Patch
github.com / python/cpython/commit/ad4d5ba32af4d80b0dfa2ba9d8203bfb219e60a5
Patch
github.com / python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48
Patch
github.com / python/cpython/commit/cc023511238ad93ecc8796157c6f9139a2bb2932
Patch
github.com / python/cpython/commit/ceac1efc66516ac387eef2c9a0ce671895b44f03
Patch
github.com / python/cpython/issues/143930
Issue TrackingPatch
github.com / python/cpython/pull/143931
Issue TrackingPatch
mail.python.org / archives/list/[email protected]/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS
Vendor Advisory