{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"High"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"python3 security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for python3 is now available for openEuler-24.03-LTS-SP3",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"Python combines remarkable power with very clear syntax. It has modules, classes, exceptions, very high level dynamic data types, and dynamic typing. There are interfaces to many system calls and libraries, as well as to various windowing systems. New built-in modules are easily written in C or C++ (or other languages, depending on the chosen implementation). Python is also usable as an extension language for applications written in other languages that need easy-to-use scripting or automation interfaces.\n\nSecurity Fix(es):\n\nThe HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.(CVE-2026-15806)\n\nThe \"stringprep\" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the \"idna\" codec) and the in_table_b2() function of the \"stringprep\" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.(CVE-2026-17084)\n\nAttacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff().(CVE-2026-18503)\n\nThe tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given. Only empty directories are created outside the destination. Member contents are still extracted inside it. To return to the destination the member's name must contain the destination directory's own final component, so extraction into a secure randomised directory is not affected. This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.(CVE-2026-19672)\n\nIn CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.(CVE-2026-82049)\n\nWhen tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.(CVE-2026-87910)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for python3 is now available for openEuler-24.03-LTS-SP3.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"High",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"python3",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2026-4010",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4010"
			},
			{
				"summary":"CVE-2026-15806",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-15806&packageName=python3"
			},
			{
				"summary":"CVE-2026-17084",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-17084&packageName=python3"
			},
			{
				"summary":"CVE-2026-18503",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-18503&packageName=python3"
			},
			{
				"summary":"CVE-2026-19672",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-19672&packageName=python3"
			},
			{
				"summary":"CVE-2026-82049",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-82049&packageName=python3"
			},
			{
				"summary":"CVE-2026-87910",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-87910&packageName=python3"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15806"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17084"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18503"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19672"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82049"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87910"
			},
			{
				"summary":"openEuler-SA-2026-4010 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-4010.json"
			}
		],
		"title":"An update for python3 is now available for openEuler-24.03-LTS-SP3",
		"tracking":{
			"initial_release_date":"2026-09-30T16:00:45+08:00",
			"revision_history":[
				{
					"date":"2026-09-30T16:00:45+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2026-09-30T16:00:45+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2026-09-30T16:00:45+08:00",
			"id":"openEuler-SA-2026-4010",
			"version":"1.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"openEuler-24.03-LTS-SP3",
									"name":"openEuler-24.03-LTS-SP3"
								},
								"name":"openEuler-24.03-LTS-SP3",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"noarch",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-help-3.11.6-43.oe2403sp3.noarch.rpm",
									"name":"python3-help-3.11.6-43.oe2403sp3.noarch.rpm"
								},
								"name":"python3-help-3.11.6-43.oe2403sp3.noarch.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"aarch64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-3.11.6-43.oe2403sp3.aarch64.rpm",
									"name":"python3-3.11.6-43.oe2403sp3.aarch64.rpm"
								},
								"name":"python3-3.11.6-43.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-debug-3.11.6-43.oe2403sp3.aarch64.rpm",
									"name":"python3-debug-3.11.6-43.oe2403sp3.aarch64.rpm"
								},
								"name":"python3-debug-3.11.6-43.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-debuginfo-3.11.6-43.oe2403sp3.aarch64.rpm",
									"name":"python3-debuginfo-3.11.6-43.oe2403sp3.aarch64.rpm"
								},
								"name":"python3-debuginfo-3.11.6-43.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-debugsource-3.11.6-43.oe2403sp3.aarch64.rpm",
									"name":"python3-debugsource-3.11.6-43.oe2403sp3.aarch64.rpm"
								},
								"name":"python3-debugsource-3.11.6-43.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-devel-3.11.6-43.oe2403sp3.aarch64.rpm",
									"name":"python3-devel-3.11.6-43.oe2403sp3.aarch64.rpm"
								},
								"name":"python3-devel-3.11.6-43.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-tkinter-3.11.6-43.oe2403sp3.aarch64.rpm",
									"name":"python3-tkinter-3.11.6-43.oe2403sp3.aarch64.rpm"
								},
								"name":"python3-tkinter-3.11.6-43.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64.rpm",
									"name":"python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64.rpm"
								},
								"name":"python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-3.11.6-43.oe2403sp3.src.rpm",
									"name":"python3-3.11.6-43.oe2403sp3.src.rpm"
								},
								"name":"python3-3.11.6-43.oe2403sp3.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"x86_64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-3.11.6-43.oe2403sp3.x86_64.rpm",
									"name":"python3-3.11.6-43.oe2403sp3.x86_64.rpm"
								},
								"name":"python3-3.11.6-43.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-debug-3.11.6-43.oe2403sp3.x86_64.rpm",
									"name":"python3-debug-3.11.6-43.oe2403sp3.x86_64.rpm"
								},
								"name":"python3-debug-3.11.6-43.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-debuginfo-3.11.6-43.oe2403sp3.x86_64.rpm",
									"name":"python3-debuginfo-3.11.6-43.oe2403sp3.x86_64.rpm"
								},
								"name":"python3-debuginfo-3.11.6-43.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-debugsource-3.11.6-43.oe2403sp3.x86_64.rpm",
									"name":"python3-debugsource-3.11.6-43.oe2403sp3.x86_64.rpm"
								},
								"name":"python3-debugsource-3.11.6-43.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-devel-3.11.6-43.oe2403sp3.x86_64.rpm",
									"name":"python3-devel-3.11.6-43.oe2403sp3.x86_64.rpm"
								},
								"name":"python3-devel-3.11.6-43.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-tkinter-3.11.6-43.oe2403sp3.x86_64.rpm",
									"name":"python3-tkinter-3.11.6-43.oe2403sp3.x86_64.rpm"
								},
								"name":"python3-tkinter-3.11.6-43.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64.rpm",
									"name":"python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64.rpm"
								},
								"name":"python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-help-3.11.6-43.oe2403sp3.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
					"name":"python3-help-3.11.6-43.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-3.11.6-43.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
					"name":"python3-3.11.6-43.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-debug-3.11.6-43.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
					"name":"python3-debug-3.11.6-43.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-debuginfo-3.11.6-43.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
					"name":"python3-debuginfo-3.11.6-43.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-debugsource-3.11.6-43.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
					"name":"python3-debugsource-3.11.6-43.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-devel-3.11.6-43.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
					"name":"python3-devel-3.11.6-43.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-tkinter-3.11.6-43.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
					"name":"python3-tkinter-3.11.6-43.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
					"name":"python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-3.11.6-43.oe2403sp3.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
					"name":"python3-3.11.6-43.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-3.11.6-43.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
					"name":"python3-3.11.6-43.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-debug-3.11.6-43.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
					"name":"python3-debug-3.11.6-43.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-debuginfo-3.11.6-43.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
					"name":"python3-debuginfo-3.11.6-43.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-debugsource-3.11.6-43.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
					"name":"python3-debugsource-3.11.6-43.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-devel-3.11.6-43.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
					"name":"python3-devel-3.11.6-43.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-tkinter-3.11.6-43.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
					"name":"python3-tkinter-3.11.6-43.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64",
					"name":"python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64 as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2026-15806",
			"notes":[
				{
					"text":"The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://. Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
					],
					"details":"python3 security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4010"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":6.0,
						"vectorString":"CVSS:3.1/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2026-15806"
		},
		{
			"cve":"CVE-2026-17084",
			"notes":[
				{
					"text":"The \"stringprep\" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the \"idna\" codec) and the in_table_b2() function of the \"stringprep\" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
					],
					"details":"python3 security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4010"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":6.0,
						"vectorString":"CVSS:3.1/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2026-17084"
		},
		{
			"cve":"CVE-2026-18503",
			"notes":[
				{
					"text":"Attacker-controlled CSV samples can trigger super-linear \nregular-expression work during dialect sniffing and consume significant \nCPU when applications pass unbounded input to csv.Sniffer.sniff().",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
					],
					"details":"python3 security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4010"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"LOW",
						"baseScore":2.4,
						"vectorString":"CVSS:3.1/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"Low",
					"category":"impact"
				}
			],
			"title":"CVE-2026-18503"
		},
		{
			"cve":"CVE-2026-19672",
			"notes":[
				{
					"text":"The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such as ../evil/../dest/sub/file. The containment check used the resolved path, but intermediate directories were created from the name as given. Only empty directories are created outside the destination. Member contents are still extracted inside it. To return to the destination the member's name must contain the destination directory's own final component, so extraction into a secure randomised directory is not affected. This affects POSIX platforms only. On Windows, .. components are collapsed before the path reaches the filesystem, so the directories outside the destination are never created.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
					],
					"details":"python3 security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4010"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":6.3,
						"vectorString":"CVSS:3.1/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2026-19672"
		},
		{
			"cve":"CVE-2026-82049",
			"notes":[
				{
					"text":"In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination directory, or expose the contents of that file within the extracted tree.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
					],
					"details":"python3 security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4010"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.4,
						"vectorString":"CVSS:3.1/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2026-82049"
		},
		{
			"cve":"CVE-2026-87910",
			"notes":[
				{
					"text":"When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls, the return value was ignored. Instead, the member should be skipped if either call returns None.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
					"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
					"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
					],
					"details":"python3 security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4010"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":5.7,
						"vectorString":"CVSS:3.1/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP3:python3-help-3.11.6-43.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.aarch64",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python3-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debug-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debuginfo-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-debugsource-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-devel-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-tkinter-3.11.6-43.oe2403sp3.x86_64",
						"openEuler-24.03-LTS-SP3:python3-unversioned-command-3.11.6-43.oe2403sp3.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2026-87910"
		}
	]
}