USN-8744-1: Python vulnerabilities
It was discovered that Python's http.cookies module incorrectly handled control characters in certain cookie operations. An attacker could possibly use this issue to inject arbitrary content. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-3644) It was discovered that the Python pyexpat module was vulnerable to unbounded recursion in the Expat XML parser. An attacker could possibly use this issue to cause Python to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-4224) It was discovered that Python's tarfile module did not correctly apply the filter parameter when extracting hard links. An attacker could possibly use this issue to cause files to be extracted with an unexpected uid or gid, bypassing the restrictions requested via filter='data'. (CVE-2026-4360) It was discovered that Python's http.cookies module incorrectly escaped values in the js_output() method. An attacker could possibly use this issue to inject arbitrary JavaScript. (CVE-2026-6019) It was discovered that Python's html.parser module incorrectly handled repeated unterminated markup declarations. An attacker could possibly use this issue to cause Python to consume excessive CPU resources, leading to a denial of service. (CVE-2026-15308)
Details
Original advisory: https://ubuntu.com/security/notices/USN-8744-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-36440.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-42240.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-43600.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-60190.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-153080.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-3644 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-4224 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-4360 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6019 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15308 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] CPython: Schwachstelle ermöglicht Denial of Servicecert-bund
- highexploited[UPDATE] [hoch] IBM QRadar SIEM: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] CPython: Mehrere Schwachstellen ermöglichen Manipulation von Dateien und DoScert-bund
- high[NEW] [high] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund
- unknownCVE-2026-3644: Incomplete control character validation in http.cookiesmsrc
- unknownCVE-2026-4224: Stack overflow parsing XML with deeply nested DTD content modelsmsrc
- highCVE-2026-15308: Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup decla…msrc
- unknownVulnerability in CPython (July 10, 2026)cert-fr-avis
- highCVE-2026-15308: The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through …nvd
- unknownUSN-8509-1: Python vulnerabilitiesubuntu
- unknownVulnerability in CPython (July 2, 2026)cert-fr-avis
- unknownCVE-2026-4360: In the Tarfile.extract() function, the filter parameter is not passed properly when extracting …nvd
More from Ubuntu Security Notices
- unknownUSN-8747-1: Beets vulnerability2026-09-10
- unknownUSN-8746-1: libEBML vulnerability2026-09-10
- unknownUSN-8745-1: KissFFT vulnerabilities2026-09-10
- unknownUSN-8748-1: Linux kernel (NVIDIA) vulnerabilities2026-09-10
- unknownUSN-8743-1: PHP vulnerabilities2026-09-10