---
cve: "CVE-2026-4519"
severity: "HIGH"
cvss: 7.0
epss: "31%"
vendor: "Python Software Foundation"
kev: false
exploited: false
published: "2026-03-20 15:16:24"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T12:17:26+02:00"
---

# CVE-2026-4519

> 7.0 HIGH · 🧪 PoC

## Beschreibung

The webbrowser.open() API would accept leading dashes in the URL which 
could be handled as command line options for certain web browsers. New 
behavior rejects leading dashes. Users are recommended to sanitize URLs 
prior to passing to webbrowser.open().

## CVSS-Vektor

```
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |

## Patch verfügbar (OSV)

- 01104ce1beb3135c2e0c01ec835b994c1f55a1c0 (Commit)
- 23116f998f6789d8c2fbe5ed5b8146854c8c2a4f (Commit)

## Referenzen

- <https://github.com/python/cpython/pull/143931>
- <https://github.com/python/cpython/issues/143930>
- <https://mail.python.org/archives/list/security-announce@python.org/thread/AY5NDSS433JK56Q7Q5IS7B37QFZVVOUS/>
- <https://github.com/python/cpython/commit/43fe06b96f6a6cf5cfd5bdab20b8649374956866>
- <https://github.com/python/cpython/commit/82a24a4442312bdcfc4c799885e8b3e00990f02b>
- <https://github.com/python/cpython/commit/9669a912a0e329c094e992204d6bdb8787024d76>
- <https://github.com/python/cpython/commit/ad4d5ba32af4d80b0dfa2ba9d8203bfb219e60a5>
- <https://github.com/python/cpython/commit/ceac1efc66516ac387eef2c9a0ce671895b44f03>
- <https://github.com/python/cpython/commit/cbba6119391112aba9c5aebf7b94aea447922c48>
- <https://github.com/python/cpython/commit/3681d47a440865aead912a054d4599087b4270dd>
- <https://github.com/python/cpython/commit/591ed890270c5697b013bf637029fb3e6cd2d73e>
- <https://github.com/python/cpython/commit/594b5a05dc9913880ac92eded440defbf32a28d1>
- <https://github.com/python/cpython/commit/89bfb8e5ed3c7caa241028f1a4eac5f6275a46a4>
- <https://github.com/python/cpython/commit/96fc5048605863c7b6fd6289643feb0e97edd96c>
- <https://github.com/python/cpython/commit/cc023511238ad93ecc8796157c6f9139a2bb2932>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-4519) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
