PT-2026-23068 · Python+1 · Cpython+1
Zoobaa
·
Published
2026-03-04
·
Updated
2026-05-19
·
CVE-2026-2297
CVSS v4.0
5.7
Medium
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CPython (affected versions not specified)
Description
The import hook in CPython that handles legacy *.pyc files using
SourcelessFileLoader is incorrectly handled within FileLoader, a base class. This results in the failure to utilize io.open code() when reading these .pyc files. Consequently, sys.audit handlers for the associated audit event do not activate as expected.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cpython
Rocky Linux