Red Hat Product Errata RHSA-2026:28247 - Security Advisory Issued: 2026-06-23 Updated: 2026-06-23 RHSA-2026:28247 - Security Advisory Overview Updated Packages Synopsis Important: python3.14 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for python3.14 is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API (CVE-2026-4786) python: Python: Cross-Site Scripting (XSS) vulnerability in http.cookies module (CVE-2026-6019) Bug Fix(es) and Enhancement(s): [9.8.z]Update python3.14 to 3.14.5 for the incremental GC changes (JIRA:RHEL-180642) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support 9.8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support 9.8 s390x Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2458049 - CVE-2026-4786 python: cpython: Python: Arbitrary code execution via command injection in webbrowser.open() API BZ - 2460869 - CVE-2026-6019 python: Python: Cross-Site Scripting (XSS) vulnerability in http.cookies module CVEs CVE-2026-4786 CVE-2026-6019 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM python3.14-3.14.5-1.el9_8.src.rpm SHA-256: a08f1c71adcd5d281d244ad7dc32e54af9fef9f89d415dacd37c6c445f2e8393 x86_64 python3.14-3.14.5-1.el9_8.x86_64.rpm SHA-256: be58628fe1c5ab5fd7660c21b3b7fbc7e9f125fb6633d605e63d493e3a064871 python3.14-debuginfo-3.14.5-1.el9_8.i686.rpm SHA-256: 367218294eaf32bc7e5988b5a32744158d40b855aabd7e5ebaa728a0bb61bbd5 python3.14-debuginfo-3.14.5-1.el9_8.x86_64.rpm SHA-256: 54a61f127fe736f85ec565fa07ea8bc20f353ddadfa514d00c60253dc30bc09e python3.14-debugsource-3.14.5-1.el9_8.i686.rpm SHA-256: 8120673808183264bc49c7a5993534d0e69d86f8d121cd0bde24a0308a6afe99 python3.14-debugsource-3.14.5-1.el9_8.x86_64.rpm SHA-256: d7e8fd61aad479cc00759193811f1c05f76fcc6aa9281df688c4d058d5a1c1b9 python3.14-devel-3.14.5-1.el9_8.i686.rpm SHA-256: 511b722cc3cea8b12b34cc2a3d9fa51cd6662456e9169b8e0b51534dc25d60a6 python3.14-devel-3.14.5-1.el9_8.x86_64.rpm SHA-256: fc0b6e11532ee9dd8bbe0e90834e7c185158e551d6740f89abb93c2845a44452 python3.14-libs-3.14.5-1.el9_8.i686.rpm SHA-256: 3ecca2dc0c7670b5f9aaac6c1ac1122a103cb2a3e31d5269d7c1bd6edf13f187 python3.14-libs-3.14.5-1.el9_8.x86_64.rpm SHA-256: 6c3db4f532e8c44f65b06fbefe8b8228155aae0eae2777551009f6c6a3d567ca python3.14-tkinter-3.14.5-1.el9_8.x86_64.rpm SHA-256: 5dbf9daeb81e6e466d35a6faa47bb61224fcbd2d266aed68c5ea12c3b5cf64a6 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM python3.14-3.14.5-1.el9_8.src.rpm SHA-256: a08f1c71adcd5d281d244ad7dc32e54af9fef9f89d415dacd37c6c445f2e8393 x86_64 python3.14-3.14.5-1.el9_8.x86_64.rpm SHA-256: be58628fe1c5ab5fd7660c21b3b7fbc7e9f125fb6633d605e63d493e3a064871 python3.14-debuginfo-3.14.5-1.el9_8.i686.rpm SHA-256: 367218294eaf32bc7e5988b5a32744158d40b855aabd7e5ebaa728a0bb61bbd5 python3.14-debuginfo-3.14.5-1.el9_8.x86_64.rpm SHA-256: 54a61f127fe736f85ec565fa07ea8bc20f353ddadfa514d00c60253dc30bc09e python3.14-debugsource-3.14.5-1.el9_8.i686.rpm SHA-256: 8120673808183264bc49c7a5993534d0e69d86f8d121cd0bde24a0308a6afe99 python3.14-debugsource-3.14.5-1.el9_8.x86_64.rpm SHA-256: d7e8fd61aad479cc00759193811f1c05f76fcc6aa9281df688c4d058d5a1c1b9 python3.14-devel-3.14.5-1.el9_8.i686.rpm SHA-256: 511b722cc3cea8b12b34cc2a3d9fa51cd6662456e9169b8e0b51534dc25d60a6 python3.14-devel-3.14.5-1.el9_8.x86_64.rpm SHA-256: fc0b6e11532ee9dd8bbe0e90834e7c185158e551d6740f89abb93c2845a44452 python3.14-libs-3.14.5-1.el9_8.i686.rpm SHA-256: 3ecca2dc0c7670b5f9aaac6c1ac1122a103cb2a3e31d5269d7c1bd6edf13f187 python3.14-libs-3.14.5-1.el9_8.x86_64.rpm SHA-256: 6c3db4f532e8c44f65b06fbefe8b8228155aae0eae2777551009f6c6a3d567ca python3.14-tkinter-3.14.5-1.el9_8.x86_64.rpm SHA-256: 5dbf9daeb81e6e466d35a6faa47bb61224fcbd2d266aed68c5ea12c3b5cf64a6 Red Hat Enterprise Linux for IBM z Systems 9 SRPM python3.14-3.14.5-1.el9_8.src.rpm SHA-256: a08f1c71adcd5d281d244ad7dc32e54af9fef9f89d415dacd37c6c445f2e8393 s390x python3.14-3.14.5-1.el9_8.s390x.rpm SHA-256: 76e51a9657bd0139076e77b981801f93b2815f536ac9d3340128b339577dbcf9 python3.14-debuginfo-3.14.5-1.el9_8.s390x.rpm SHA-256: e9e5ef82bf96ce8f387ea7fa74b400725b5af283532ad3c31190623d1d07ccca python3.14-debugsource-3.14.5-1.el9_8.s390x.rpm SHA-256: b51a3993b78b5179bdfed2429d9299e4a22ead04f804653e8a8fcf19a834072a python3.14-devel-3.14.5-1.el9_8.s390x.rpm SHA-256: 19c8464c31f79344cc1e4558e407f13b8055ae1006c6ed1b8ac7b7b110f2116c python3.14-libs-3.14.5-1.el9_8.s390x.rpm SHA-256: c158a015c61f762eb7da7875b779aaac1b1ebaa2bffc70b2ef2d2253bbff7845 python3.14-tkinter-3.14.5-1.el9_8.s390x.rpm SHA-256: 4200b14cb336c4c28d01e06fa327b7c63ab9e57cb91cf1f85fb4114e220c0ba6 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 SRPM python3.14-3.14.5-1.el9_8.src.rpm SHA-256: a08f1c71adcd5d281d244ad7dc32e54af9fef9f89d415dacd37c6c445f2e8393 s390x python3.14-3.14.5-1.el9_8.s390x.rpm SHA-256: 76e51a9657bd0139076e77b981801f93b2815f536ac9d3340128b339577dbcf9 python3.14-debuginfo-3.14.5-1.el9_8.s390x.rpm SHA-256: e9e5ef82bf96ce8f387ea7fa74b400725b5af283532ad3c31190623d1d07ccca python3.14-debugsource-3.14.5-1.el9_8.s390x.rpm SHA-256: b51a3993b78b5179bdfed2429d9299e4a22ead04f804653e8a8fcf19a834072a python3.14-devel-3.14.5-1.el9_8.s390x.rpm SHA-256: 19c8464c31f79344cc1e4558e407f13b8055ae1006c6ed1b8ac7b7b110f2116c python3.14-libs-3.14.5-1.el9_8.s390x.rpm SHA-256: c158a015c61f762eb7da7875b779aaac1b1ebaa2bffc70b2ef2d2253bbff7845 python3.14-tkinter-3.14.5-1.el9_8.s390x.rpm SHA-256: 4200b14cb336c4c28d01e06fa327b7c63ab9e57cb91cf1f85fb4114e220c0ba6 Red Hat Enterprise Linux for Power, little endian 9 SRPM python3.14-3.14.5-1.el9_8.src.rpm SHA-256: a08f1c71adcd5d281d244ad7dc32e54af9fef9f89d415dacd37c6c445f2e8393 ppc64le python3.14-3.14.5-1.el9_8.ppc64le.rpm SHA-256: ebf3732017c8016babfd2aba96ebf91fb815b98d14367bb7c625d79c74a493d5 python3.14-debuginfo-3.14.5-1.el9_8.ppc64le.rpm SHA-256: 7991c8fc1a1566b45b8b6764d9fc9c08fb746ae156376a8ccc8d52b5817be329 python3.14-debugsource-3.14.5-1.el9_8.ppc64le.rpm SHA-256: de4f61a6bc5596aaf8efb99bb1339dfc39e12ec07d1d68bf076e90855353c674 python3.14-devel-3.14.5-1.el9_8.ppc64le.rpm SHA-256: dc4b9418f179bb6ea8bf3b33e45c431aefd9687e743083b4ccea522b0b80c884 python3.14-libs-3.14.5-1.el9_8.ppc64le.rpm SHA-256: 16cff016123bf5f9b8e288ccfceb09a6794d5be6a7b40f7e1a626614e095c8d0 python3.14-tkinter-3.14.5-1.el9_8.ppc64le.rpm SHA-256: 9aea7ff98175235723581a0b563860b3e1f431ed3e04771725a6b19c0b6ed1ce Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 SRPM python3.14-3.14.5-1.el9_8.src.rpm SHA-256: a08f1c71adcd5d281d244ad7dc32e54af9fef9f89d415dacd37c6c445f2e8393 ppc64le python3.14-3.14.5-1.el9_8.ppc64le.rpm SHA-256: ebf3732017c8016babfd2aba96ebf91fb815b98d14367bb7c625d79c74a493d5 python3.14-debuginfo-3.14.5-1.el9_8.ppc64le.rpm SHA-256: 7991c8fc1a1566b45b8b6764d9fc9c08fb746ae156376a8ccc8d52b5817be329 python3.14-debugsource-3.14.5-1.el9_8.ppc64le.rpm SHA-256: de4f61a6bc5596aaf8efb99bb1339dfc39e12ec07d1d68bf076e90855353c674 python3.14-devel-3.14.5-1.el9_8.ppc64le.rpm SHA-256: dc4b9418f179bb6ea8bf3b33e45c431aefd9687e743083b4ccea522b0b80c884 python3.14-libs-3.14.5-1.el9_8.ppc64le.rpm SHA-256: 16cff016123bf5f9b8e288ccfceb09
This update addresses two vulnerabilities in Python: CVE-2026-4786, which allows arbitrary code execution via command injection in the `webbrowser.open()` API, and CVE-2026-6019, a Cross-Site Scripting (XSS) flaw in the `http.cookies` module, both with a CVSS score of 6.1 (MEDIUM). According to the authoritative NVD data, the affected versions are Python versions prior to 3.15.0. The fix requires upgrading to Python version 3.15.0.