USN-8744-1: Python vulnerabilities

Publication date

10 September 2026

Overview

Several security issues were fixed in Python.


Packages

  • python2.7 - An interactive high-level object-oriented language
  • python3.10 - An interactive high-level object-oriented language
  • python3.11 - An interactive high-level object-oriented language
  • python3.12 - An interactive high-level object-oriented language
  • python3.14 - An interactive high-level object-oriented language
  • python3.4 - An interactive high-level object-oriented language
  • python3.5 - An interactive high-level object-oriented language
  • python3.6 - An interactive high-level object-oriented language
  • python3.7 - An interactive high-level object-oriented language
  • python3.8 - An interactive high-level object-oriented language
  • python3.9 - An interactive high-level object-oriented language

Details

It was discovered that Python's http.cookies module incorrectly handled
control characters in certain cookie operations. An attacker could possibly
use this issue to inject arbitrary content. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-3644)

It was discovered that the Python pyexpat module was vulnerable to
unbounded recursion in the Expat XML parser. An attacker could possibly use
this issue to cause Python to crash, resulting in a denial of service. This
issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-4224)

It was discovered that Python's tarfile module did not correctly apply the
filter parameter when extracting hard links. An attacker could possibly...

It was discovered that Python's http.cookies module incorrectly handled
control characters in certain cookie operations. An attacker could possibly
use this issue to inject arbitrary content. This issue only affected
Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-3644)

It was discovered that the Python pyexpat module was vulnerable to
unbounded recursion in the Expat XML parser. An attacker could possibly use
this issue to cause Python to crash, resulting in a denial of service. This
issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-4224)

It was discovered that Python's tarfile module did not correctly apply the
filter parameter when extracting hard links. An attacker could possibly use
this issue to cause files to be extracted with an unexpected uid or gid,
bypassing the restrictions requested via filter='data'. (CVE-2026-4360)

It was discovered that Python's http.cookies module incorrectly escaped
values in the js_output() method. An attacker could possibly use this issue
to inject arbitrary JavaScript. (CVE-2026-6019)

It was discovered that Python's html.parser module incorrectly handled
repeated unterminated markup declarations. An attacker could possibly use
this issue to cause Python to consume excessive CPU resources, leading to a
denial of service. (CVE-2026-15308)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute libpython3.14 –  3.14.4-1ubuntu0.2
python3.14 –  3.14.4-1ubuntu0.2
24.04 LTS noble libpython3.12t64 –  3.12.3-1ubuntu0.17
python3.12 –  3.12.3-1ubuntu0.17
22.04 LTS jammy libpython2.7 –  2.7.18-13ubuntu1.5+esm9  
libpython3.10 –  3.10.12-1~22.04.18
libpython3.11 –  3.11.0~rc1-1~22.04.1+esm2  
python2.7 –  2.7.18-13ubuntu1.5+esm9  
python3.10 –  3.10.12-1~22.04.18
python3.11 –  3.11.0~rc1-1~22.04.1+esm2  
20.04 LTS focal libpython2.7 –  2.7.18-1~20.04.7+esm10  
libpython3.8 –  3.8.10-0ubuntu1~20.04.18+esm7  
libpython3.9 –  3.9.5-3ubuntu0~20.04.1+esm11  
python2.7 –  2.7.18-1~20.04.7+esm10  
python3.8 –  3.8.10-0ubuntu1~20.04.18+esm7  
python3.9 –  3.9.5-3ubuntu0~20.04.1+esm11  
18.04 LTS bionic libpython2.7 –  2.7.17-1~18.04ubuntu1.13+esm15  
libpython3.6 –  3.6.9-1~18.04ubuntu1.13+esm10  
libpython3.7 –  3.7.5-2ubuntu1~18.04.2+esm11  
libpython3.8 –  3.8.0-3ubuntu1~18.04.2+esm11  
python2.7 –  2.7.17-1~18.04ubuntu1.13+esm15  
python3.6 –  3.6.9-1~18.04ubuntu1.13+esm10  
python3.7 –  3.7.5-2ubuntu1~18.04.2+esm11  
python3.8 –  3.8.0-3ubuntu1~18.04.2+esm11  
16.04 LTS xenial libpython2.7 –  2.7.12-1ubuntu0~16.04.18+esm22  
libpython3.5 –  3.5.2-2ubuntu0~16.04.13+esm25  
python2.7 –  2.7.12-1ubuntu0~16.04.18+esm22  
python3.5 –  3.5.2-2ubuntu0~16.04.13+esm25  
14.04 LTS trusty libpython2.7 –  2.7.6-8ubuntu0.6+esm30  
libpython3.4 –  3.4.3-1ubuntu1~14.04.7+esm21  
libpython3.5 –  3.5.2-2ubuntu0~16.04.4~14.04.1+esm11  
python2.7 –  2.7.6-8ubuntu0.6+esm30  
python3.4 –  3.4.3-1ubuntu1~14.04.7+esm21  
python3.5 –  3.5.2-2ubuntu0~16.04.4~14.04.1+esm11  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›