could be handled as command line options for certain web browsers. New
behavior rejects leading dashes. Users are recommended to sanitize URLs
prior to passing to webbrowser.open().
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4583-1 | python3.9 security update |
Thu, 16 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python python
|
|
| CPEs | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha1:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha2:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha3:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha4:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha5:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha6:*:*:*:*:*:* cpe:2.3:a:python:python:3.15.0:alpha7:*:*:*:*:*:* |
|
| Vendors & Products |
Python python
|
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 07 Apr 2026 20:45:00 +0000
Wed, 25 Mar 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 25 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 | |
| Metrics |
ssvc
|
Tue, 24 Mar 2026 19:30:00 +0000
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python
Python cpython |
|
| Vendors & Products |
Python
Python cpython |
Sat, 21 Mar 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 20 Mar 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 20 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
cvssV4_0
|
Fri, 20 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior rejects leading dashes. Users are recommended to sanitize URLs prior to passing to webbrowser.open(). | |
| Title | webbrowser.open() allows leading dashes in URLs | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: PSF
Published:
Updated: 2026-04-13T21:47:40.137Z
Reserved: 2026-03-20T15:01:11.126Z
Link: CVE-2026-4519
Updated: 2026-03-20T20:07:08.244Z
Status : Analyzed
Published: 2026-03-20T15:16:24.057
Modified: 2026-04-16T14:53:22.860
Link: CVE-2026-4519
OpenCVE Enrichment
Updated: 2026-03-25T21:28:16Z
Debian DLA