FlawAtlas
Search the atlas
CVE-2026-0864 Moderate

CVE-2026-0864

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

Exploit probability 0.1%
Published June 23, 2026
Required by Not available
Last source change August 11, 2026

02 / AFFECTED SOFTWARE

Affected packages

Bitnami python
Bitnami python-min
Bitnami libpython
Unknown Unknown

247 explicit affected versions

Unknown Unknown

229 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-0864

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

View original source
Open Source Vulnerabilities BIT-python-min-2026-0864

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

View original source
Open Source Vulnerabilities BIT-python-2026-0864

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

View original source
Open Source Vulnerabilities BIT-libpython-2026-0864

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

View original source
Open Source Vulnerabilities PSF-2026-29

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

View original source

05 / REFERENCES

Further evidence