Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5713

22
FAUCET Score

OVERVIEW CVE-2026-5713 affects Python 3.15+ profiling.sampling module and asyncio introspection capabilities (3.14+), including features like "python -m asyncio ps" and "python -m asyncio pstree." The vulnerability allows an attacker to read and write addresses in a privileged process by connecting through the remote debugging feature to a malicious or compromised Python process. SEVERITY The attack requires local network access and persistence, as an attacker must repeatedly establish connections to the target process even after crashes caused by Address Space Layout Randomization (ASLR) protections. While the attack complexity is high due to these barriers, successful exploitation could result in arbitrary code execution within a privileged process, representing a significant integrity and confidentiality impact. The CVSS score is currently unavailable, though the EPSS score of 0.00017 indicates extremely low probability of exploitation in the wild relative to other vulnerabilities. EXPLOITATION STATUS This vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no signs of active exploitation. The vulnerability remains on the inactive Hot List, with no publicly available exploit code reported. Community attention appears minimal, consistent with the low EPSS score and the technical barriers required for successful exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.14.0, < 3.14.5CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.3MEDIUM

CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
HIGH
User Interaction
ACTIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
3.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 26th percentile among its peer group of 74 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

ubuntupatch availablevia ubuntu_usn
Product: python3.10 (jammy)Fixed in: 3.10.12-1~22.04.16
ubuntupatch availablevia ubuntu_usn
Product: python3.12 (noble)Fixed in: 3.12.3-1ubuntu0.15
ubuntupatch availablevia ubuntu_usn
Product: python3.14 (resolute)Fixed in: 3.14.4-1ubuntu0.1

Vendor Advisories (1)

ubuntuUSN-8509-1

Python vulnerabilities

Jul 6, 2026

References

openwall.com / lists/oss-security/2026/04/15/6
github.com / python/cpython/commit/289fd2c97a7e5aecb8b69f94f5e838ccfeee7e67
github.com / python/cpython/commit/316f6265b7f9ca4ffed5346b747475ef1943f35d
github.com / python/cpython/issues/148178
github.com / python/cpython/pull/148187
mail.python.org / archives/list/[email protected]/thread/OG4RHARYSNIE22GGOMVMCRH76L5HKPLM