Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:6285 - Security Advisory
Issued:
2026-03-31
Updated:
2026-03-31

RHSA-2026:6285 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: python3.12 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for python3.12 is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • python: Python: Command-line option injection in webbrowser.open() via crafted URLs (CVE-2026-4519)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x

Fixes

  • BZ - 2449649 - CVE-2026-4519 python: Python: Command-line option injection in webbrowser.open() via crafted URLs

CVEs

  • CVE-2026-4519

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
python3.12-3.12.12-4.el9_7.2.src.rpm SHA-256: 0d4494e18c3a6b5c62c96ef5786561fc6fab96cd50f2380c1471d2eaeabd06fd
x86_64
python3.12-3.12.12-4.el9_7.2.x86_64.rpm SHA-256: 37b577f725f5ccc863f6d651585954153754e7e6bcbe9058d80f9d6e70f7c439
python3.12-debuginfo-3.12.12-4.el9_7.2.i686.rpm SHA-256: 90b9e622d75ad67ff171dc6a5633bb4d89e27e74a72b9bc31ab30f5649f6f6a8
python3.12-debuginfo-3.12.12-4.el9_7.2.x86_64.rpm SHA-256: a4e9226bfd859b7db50a76e9063e960a31cfc303d98cd7c7f0887c3ba7271bb5
python3.12-debugsource-3.12.12-4.el9_7.2.i686.rpm SHA-256: 4516d698d8809971c12f45f873e85f8303431ffbaa732460462b81ad7caee6ba
python3.12-debugsource-3.12.12-4.el9_7.2.x86_64.rpm SHA-256: b1af1d88b340163f9ff205fc32e716b498a9111147eff6e70df4edb43ca3308a
python3.12-devel-3.12.12-4.el9_7.2.i686.rpm SHA-256: 82cea5a4faed8fd957110b987f9c07a6774fd37d5c3b7754d047b6a8f0188f4b
python3.12-devel-3.12.12-4.el9_7.2.x86_64.rpm SHA-256: 3ae0df091c090782f4f26cc532835ca86c73d308afb40b78c8cf7191b7c4dad5
python3.12-libs-3.12.12-4.el9_7.2.i686.rpm SHA-256: 8bd2696ef0949d26346ea7792cf04161152a0b6b8a8c5d441168eb6724f489e6
python3.12-libs-3.12.12-4.el9_7.2.x86_64.rpm SHA-256: b585cdcc008fb29fbccec4f0bc7cf1478930bd7c3103b380ea04ab66a7dac414
python3.12-tkinter-3.12.12-4.el9_7.2.x86_64.rpm SHA-256: 7d697096afebf7edcfd5f2b86e5e5677f8052cfac814ad2144e182a42a463d89

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
python3.12-3.12.12-4.el9_7.2.src.rpm SHA-256: 0d4494e18c3a6b5c62c96ef5786561fc6fab96cd50f2380c1471d2eaeabd06fd
s390x
python3.12-3.12.12-4.el9_7.2.s390x.rpm SHA-256: 119db15b5df8df92bed4dd15c26d5d04cdf8e1d36dfebf732165818c6742751b
python3.12-debuginfo-3.12.12-4.el9_7.2.s390x.rpm SHA-256: a7a76544f93e83abcb217ebb4742a33eaaee48ff808b2e9930ed91cece845809
python3.12-debugsource-3.12.12-4.el9_7.2.s390x.rpm SHA-256: f5a51ab8ba823bdf257b0a65c60c9f96dfe7a7e91c6f9d3da79ef7fe29fc6d13
python3.12-devel-3.12.12-4.el9_7.2.s390x.rpm SHA-256: 7fb9a893a5b42fd05e63955ab69d04c60f6700befced70b2979efe98aea595e1
python3.12-libs-3.12.12-4.el9_7.2.s390x.rpm SHA-256: 01d5e75e5d85f769c03d24e9a80456b0330f3f8c9353115cd8364a482043d041
python3.12-tkinter-3.12.12-4.el9_7.2.s390x.rpm SHA-256: f7399fb2b7c98bd5830f2295ad4f331be2e8b31349f3cd8a2b1235e689ebf82b

Red Hat Enterprise Linux for Power, little endian 9

SRPM
python3.12-3.12.12-4.el9_7.2.src.rpm SHA-256: 0d4494e18c3a6b5c62c96ef5786561fc6fab96cd50f2380c1471d2eaeabd06fd
ppc64le
python3.12-3.12.12-4.el9_7.2.ppc64le.rpm SHA-256: df48b88f619974806aa26e56218b32e86b1996718c9e1dfd9ca1d9a77d039ec3
python3.12-debuginfo-3.12.12-4.el9_7.2.ppc64le.rpm SHA-256: 5b77a985ee9611014e59656479f9a42f66075cf04da815781985694102c1efda
python3.12-debugsource-3.12.12-4.el9_7.2.ppc64le.rpm SHA-256: 5ffbbff815400eeea8fd8fb4fef241b87227081d3f4dcc7f8b007ae698d32857
python3.12-devel-3.12.12-4.el9_7.2.ppc64le.rpm SHA-256: aa58e69e6732f7c21a11717f8d56d1bca93d5e88fffb0f0b05c7de86778f6a48
python3.12-libs-3.12.12-4.el9_7.2.ppc64le.rpm SHA-256: b9b9d3119c30def6fb374bc43594af52bd0ab6cb54465d83f10b8f73fc9563d0
python3.12-tkinter-3.12.12-4.el9_7.2.ppc64le.rpm SHA-256: 532562cd4b00fa07fce556519ba48222e1568e9c33bf36dd1c4b272634285754

Red Hat Enterprise Linux for ARM 64 9

SRPM
python3.12-3.12.12-4.el9_7.2.src.rpm SHA-256: 0d4494e18c3a6b5c62c96ef5786561fc6fab96cd50f2380c1471d2eaeabd06fd
aarch64
python3.12-3.12.12-4.el9_7.2.aarch64.rpm SHA-256: e4b898a306c9199feb6d72ec8f3c6fb6736e339a9a9e787a19732decb9c2c4c6
python3.12-debuginfo-3.12.12-4.el9_7.2.aarch64.rpm SHA-256: 01ca500556ce9279452281c04aef584d18e12eea1e2c5a3846a5aa5172dd8780
python3.12-debugsource-3.12.12-4.el9_7.2.aarch64.rpm SHA-256: bb47db65143fb10c1193ae8536d273bd2bce28c9fcf6c4c6f7b20041ddd8465c
python3.12-devel-3.12.12-4.el9_7.2.aarch64.rpm SHA-256: 4481087f395c732dd7341452cc567af37bcafec1f803bdf9a81389b367c7fdd1
python3.12-libs-3.12.12-4.el9_7.2.aarch64.rpm SHA-256: 6cc853fb09b9b81fe4da67619cd8b879e2ccfd9d16f617e597cb0759e62fbb0c
python3.12-tkinter-3.12.12-4.el9_7.2.aarch64.rpm SHA-256: a7addf7a8c8dbba97ee1f6780a01f7c3d6925cf648e488eec106c1fbbc2ab5c9

Red Hat CodeReady Linux Builder for x86_64 9

SRPM
x86_64
python3.12-3.12.12-4.el9_7.2.i686.rpm SHA-256: 9a527d3391c0ef1ee755af4f6fb890205e68e3f4ffce936d417d8f6bf888a609
python3.12-debug-3.12.12-4.el9_7.2.i686.rpm SHA-256: e8704b8b5e95b094cd997a11f478754e1f0f4d7ddf90680e67fe20b6a05ac294
python3.12-debug-3.12.12-4.el9_7.2.x86_64.rpm SHA-256: fc52bbfb6327b1e7b28f608e69d6e35b30987c7ed7444c080dcf5822bbbc75b7
python3.12-debuginfo-3.12.12-4.el9_7.2.i686.rpm SHA-256: 90b9e622d75ad67ff171dc6a5633bb4d89e27e74a72b9bc31ab30f5649f6f6a8
python3.12-debuginfo-3.12.12-4.el9_7.2.x86_64.rpm SHA-256: a4e9226bfd859b7db50a76e9063e960a31cfc303d98cd7c7f0887c3ba7271bb5
python3.12-debugsource-3.12.12-4.el9_7.2.i686.rpm SHA-256: 4516d698d8809971c12f45f873e85f8303431ffbaa732460462b81ad7caee6ba
python3.12-debugsource-3.12.12-4.el9_7.2.x86_64.rpm SHA-256: b1af1d88b340163f9ff205fc32e716b498a9111147eff6e70df4edb43ca3308a
python3.12-idle-3.12.12-4.el9_7.2.i686.rpm SHA-256: b9b1c543de3fb36f44d0145fe4feb1a794679b19dcc6312178605d4df3c5fec8
python3.12-idle-3.12.12-4.el9_7.2.x86_64.rpm SHA-256: 1bba63f84da25e2ddaffffcf1c1b24766f2dffa23f841dcdf0e61deb0ce3259b
python3.12-test-3.12.12-4.el9_7.2.i686.rpm SHA-256: 138bd183b32ce5bf59c68af143b00359e8f5882ab613fa17c952f483fe91b192
python3.12-test-3.12.12-4.el9_7.2.x86_64.rpm SHA-256: 5d3845399c655ab885cdc7886a956702847ccbd4f7830c7e059d752c90816fd2
python3.12-tkinter-3.12.12-4.el9_7.2.i686.rpm SHA-256: 0053afc575b88941b47c70d708ea5774281e3b56c9e3db97992a5a30befd300d

Red Hat CodeReady Linux Builder for Power, little endian 9

SRPM
ppc64le
python3.12-debug-3.12.12-4.el9_7.2.ppc64le.rpm SHA-256: 4bc39221674239e6cdf09ba082b7de2426f9c285c4b2e40bc4b564d60a39b500
python3.12-debuginfo-3.12.12-4.el9_7.2.ppc64le.rpm SHA-256: 5b77a985ee9611014e59656479f9a42f66075cf04da815781985694102c1efda
python3.12-debugsource-3.12.12-4.el9_7.2.ppc64le.rpm SHA-256: 5ffbbff815400eeea8fd8fb4fef241b87227081d3f4dcc7f8b007ae698d32857
python3.12-idle-3.12.12-4.el9_7.2.ppc64le.rpm SHA-256: df2fc0f3e1c7cac45bbbb33c0baa101c89a5c2ea10fbd1dd4be6852aaa39f7ec
python3.12-test-3.12.12-4.el9_7.2.ppc64le.rpm SHA-256: 36ed76fd4c1480fbc83ee90f605724c0eb5116263a771bb3ce0896726d9be8f5

Red Hat CodeReady Linux Builder for ARM 64 9

SRPM
aarch64
python3.12-debug-3.12.12-4.el9_7.2.aarch64.rpm SHA-256: 3f229f0719790698578f0a4500160f2f7dada8319bd3f373434bf6bce8bac3b1
python3.12-debuginfo-3.12.12-4.el9_7.2.aarch64.rpm SHA-256: 01ca500556ce9279452281c04aef584d18e12eea1e2c5a3846a5aa5172dd8780
python3.12-debugsource-3.12.12-4.el9_7.2.aarch64.rpm SHA-256: bb47db65143fb10c1193ae8536d273bd2bce28c9fcf6c4c6f7b20041ddd8465c
python3.12-idle-3.12.12-4.el9_7.2.aarch64.rpm SHA-256: e6d2ddae9eec172ed30c59f1c333e7014d7c551cc85f0c4189a5688054a7b98a
python3.12-test-3.12.12-4.el9_7.2.aarch64.rpm SHA-256: 65cb4d0775664eecedb95f366b5b5aaebb734ab1ee2003caf6f317424f818346

Red Hat CodeReady Linux Builder for IBM z Systems 9

SRPM
s390x
python3.12-debug-3.12.12-4.el9_7.2.s390x.rpm SHA-256: 92e459b564f362c11524c311f98e81f9ce1e724c25e599f30e87e375c095dccd
python3.12-debuginfo-3.12.12-4.el9_7.2.s390x.rpm SHA-256: a7a76544f93e83abcb217ebb4742a33eaaee48ff808b2e9930ed91cece845809
python3.12-debugsource-3.12.12-4.el9_7.2.s390x.rpm SHA-256: f5a51ab8ba823bdf257b0a65c60c9f96dfe7a7e91c6f9d3da79ef7fe29fc6d13
python3.12-idle-3.12.12-4.el9_7.2.s390x.rpm SHA-256: 2b80dfc908f5fd99e4d5f061aae01d780a6c645560295e215ab978d3e2cacd8e
python3.12-test-3.12.12-4.el9_7.2.s390x.rpm SHA-256: 815d8d31391bf0d1c359a202dd32d078d86324a716b76b974e54c8afe76a6315

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility