Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:6766 - Security Advisory
Issued:
2026-04-07
Updated:
2026-04-07

RHSA-2026:6766 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: python3.9 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for python3.9 is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • python: Python: Command-line option injection in webbrowser.open() via crafted URLs (CVE-2026-4519)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x

Fixes

  • BZ - 2449649 - CVE-2026-4519 python: Python: Command-line option injection in webbrowser.open() via crafted URLs

CVEs

  • CVE-2026-4519

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
python3.9-3.9.25-3.el9_7.2.src.rpm SHA-256: 49478bd870dd15419f6720a2c179dee6efc7c23953ea11248091bd864db931cb
x86_64
python-unversioned-command-3.9.25-3.el9_7.2.noarch.rpm SHA-256: fc54f541bf440db47821e9c5055bcff5a624abb795f697148469fac6ed150f19
python3-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: e90bec441c9e7f22c362ef88e8c73dcff9d3e5287c4fcca77f300bcffbfb35a5
python3-devel-3.9.25-3.el9_7.2.i686.rpm SHA-256: 7d4484923fa25069c4f3edbb7e0a8b17dc0cef0aab761f7041521766f529ecf0
python3-devel-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: 29ed952493ca611688e8a5e5ffa6c352440f056d736b347757116206f5fe29b2
python3-libs-3.9.25-3.el9_7.2.i686.rpm SHA-256: 2aab8a9db5268e500af2d0bb7c9bd861e8da93342d0d773f12dbfeffa6fde01d
python3-libs-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: 63977a71bc8bc289bc0cdf9e51f21ecd46a81cfab760002d58266bb739975640
python3-tkinter-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: 3509b972c1832a76f8a1ae4458a0999a6558cf32ede497aad86c3fc947188867
python3.9-debuginfo-3.9.25-3.el9_7.2.i686.rpm SHA-256: e79ba4b4e515698d89e318d1704d47f4a18323e5accf8edab5f6d21e105b1a05
python3.9-debuginfo-3.9.25-3.el9_7.2.i686.rpm SHA-256: e79ba4b4e515698d89e318d1704d47f4a18323e5accf8edab5f6d21e105b1a05
python3.9-debuginfo-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: 170ac29bbc3d90bad07ef0ff2e3d6bed538a479f7e1edbae400cd265153c150a
python3.9-debuginfo-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: 170ac29bbc3d90bad07ef0ff2e3d6bed538a479f7e1edbae400cd265153c150a
python3.9-debugsource-3.9.25-3.el9_7.2.i686.rpm SHA-256: 2d92c51c0474d464e19583841479f806ec84f19c6821370ae9ab992f9b2c929a
python3.9-debugsource-3.9.25-3.el9_7.2.i686.rpm SHA-256: 2d92c51c0474d464e19583841479f806ec84f19c6821370ae9ab992f9b2c929a
python3.9-debugsource-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: 43c1971f6a81d9552e8e71e8d86f7b1667e77128fdea0e32d0c4da790db6a5a6
python3.9-debugsource-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: 43c1971f6a81d9552e8e71e8d86f7b1667e77128fdea0e32d0c4da790db6a5a6

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
python3.9-3.9.25-3.el9_7.2.src.rpm SHA-256: 49478bd870dd15419f6720a2c179dee6efc7c23953ea11248091bd864db931cb
s390x
python-unversioned-command-3.9.25-3.el9_7.2.noarch.rpm SHA-256: fc54f541bf440db47821e9c5055bcff5a624abb795f697148469fac6ed150f19
python3-3.9.25-3.el9_7.2.s390x.rpm SHA-256: 21ffbe3e0c7cdd9e7d25c003b835745efb42c7d756ac7ab010a0cec1f341f74c
python3-devel-3.9.25-3.el9_7.2.s390x.rpm SHA-256: 2d4fd761e59b80611806df8c9f4c6f2dd5fddba6fbfe037e8074deb87862c14b
python3-libs-3.9.25-3.el9_7.2.s390x.rpm SHA-256: 5bee9cd98630e50e014de39be223977eec04201fda4c0a0c0b81ab1f45b2023a
python3-tkinter-3.9.25-3.el9_7.2.s390x.rpm SHA-256: e7356290cbf8ba3049d6afe22c71241d83776cb0cccc3a7f04ea2b40cf80100f
python3.9-debuginfo-3.9.25-3.el9_7.2.s390x.rpm SHA-256: a347900fac19e42934fd4748f1e30444c9e592ceb9e05b3d036aa3fdeed22be2
python3.9-debuginfo-3.9.25-3.el9_7.2.s390x.rpm SHA-256: a347900fac19e42934fd4748f1e30444c9e592ceb9e05b3d036aa3fdeed22be2
python3.9-debugsource-3.9.25-3.el9_7.2.s390x.rpm SHA-256: 34f92261e788492b64a3a17481e103b0c6d44caa6d56808001e5d23639915e42
python3.9-debugsource-3.9.25-3.el9_7.2.s390x.rpm SHA-256: 34f92261e788492b64a3a17481e103b0c6d44caa6d56808001e5d23639915e42

Red Hat Enterprise Linux for Power, little endian 9

SRPM
python3.9-3.9.25-3.el9_7.2.src.rpm SHA-256: 49478bd870dd15419f6720a2c179dee6efc7c23953ea11248091bd864db931cb
ppc64le
python-unversioned-command-3.9.25-3.el9_7.2.noarch.rpm SHA-256: fc54f541bf440db47821e9c5055bcff5a624abb795f697148469fac6ed150f19
python3-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: f49cb9a5fe7593f0191fc2b9d3c6a4484190805f4f546af78de386a952a859ee
python3-devel-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: 5f51c2eeb1a457bef3b7a617473e0c3286e98fe9db7fe0c99006c626b87e2b6e
python3-libs-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: 6160361ca480d14ea505f6afd71f83ba1a9bb6fbd2a1a91b07ce0f377e80b0c8
python3-tkinter-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: 616e495af904918c9d92d41370130f3ecb866b05fcea661a1dd796ef713feb69
python3.9-debuginfo-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: a472b41747934edb8bdf3059a53e0f2b103506db0240635ada2ade750988e4e9
python3.9-debuginfo-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: a472b41747934edb8bdf3059a53e0f2b103506db0240635ada2ade750988e4e9
python3.9-debugsource-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: f655ae77aef5631a894ac4aa2ef397b58227f25674bb564a2a8c7772fdaf85ae
python3.9-debugsource-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: f655ae77aef5631a894ac4aa2ef397b58227f25674bb564a2a8c7772fdaf85ae

Red Hat Enterprise Linux for ARM 64 9

SRPM
python3.9-3.9.25-3.el9_7.2.src.rpm SHA-256: 49478bd870dd15419f6720a2c179dee6efc7c23953ea11248091bd864db931cb
aarch64
python-unversioned-command-3.9.25-3.el9_7.2.noarch.rpm SHA-256: fc54f541bf440db47821e9c5055bcff5a624abb795f697148469fac6ed150f19
python3-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: abc463c51d898bf83da87b9d420a8d0a1c2f84a9cd73871025b3cd74d7330a21
python3-devel-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: c159fb4b0352a7889f26f0ddd8054d0cc7ae55e7633d4f73d1868e4737aaf826
python3-libs-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: 6c00141c14a30ee09284a293871e0636612082b80b4c6657db3ba24816f95cc8
python3-tkinter-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: 8195d529847302f901035463f97da068023ecb3f53e24b90ad10e48442a5197f
python3.9-debuginfo-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: 76b7583eb2b265f4f2048e3403f0ec66201a3fe0a3d55dceba24e8cd4e23debd
python3.9-debuginfo-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: 76b7583eb2b265f4f2048e3403f0ec66201a3fe0a3d55dceba24e8cd4e23debd
python3.9-debugsource-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: 483a1a04d9869831f642cad3f8f11f4f2a527d8002aefa3f2999e16cb752dcc2
python3.9-debugsource-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: 483a1a04d9869831f642cad3f8f11f4f2a527d8002aefa3f2999e16cb752dcc2

Red Hat CodeReady Linux Builder for x86_64 9

SRPM
x86_64
python3-3.9.25-3.el9_7.2.i686.rpm SHA-256: 6dfadb7842542d3cd11e7fc90a06a37a5074cfc6c5841488f57ab00a9cc5f9ee
python3-debug-3.9.25-3.el9_7.2.i686.rpm SHA-256: dc7a3fc3ef0ca13b6a19bf29e94e4b8db6d9c5364bb0f840dbc0189c2263dd0c
python3-debug-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: 800a0e780bb139810e66c20873cd0c20539bf29e3e14eedb49532f0d26522649
python3-idle-3.9.25-3.el9_7.2.i686.rpm SHA-256: ea136312fdfc07ed5e2da936855b4a6478df8485b552a40497429ce6a8a0c04d
python3-idle-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: bdb40991eb5214624f1d57b079b0fe51974772a5b3c482e07aeeea5e7e3d2d04
python3-test-3.9.25-3.el9_7.2.i686.rpm SHA-256: d21d0081743a6c0f69abfa3366aa36706fd6f09f75145c7cb45b3c32ae40effc
python3-test-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: 2f7c8e617f5611216260b90a2a3f7dcbe8a7895cf27caee2910983aa08912fe4
python3-tkinter-3.9.25-3.el9_7.2.i686.rpm SHA-256: 52be15c0a7f972e5f3f98d0eab7f065e106882fe2be5991f742165e006a1c900
python3.9-debuginfo-3.9.25-3.el9_7.2.i686.rpm SHA-256: e79ba4b4e515698d89e318d1704d47f4a18323e5accf8edab5f6d21e105b1a05
python3.9-debuginfo-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: 170ac29bbc3d90bad07ef0ff2e3d6bed538a479f7e1edbae400cd265153c150a
python3.9-debugsource-3.9.25-3.el9_7.2.i686.rpm SHA-256: 2d92c51c0474d464e19583841479f806ec84f19c6821370ae9ab992f9b2c929a
python3.9-debugsource-3.9.25-3.el9_7.2.x86_64.rpm SHA-256: 43c1971f6a81d9552e8e71e8d86f7b1667e77128fdea0e32d0c4da790db6a5a6

Red Hat CodeReady Linux Builder for Power, little endian 9

SRPM
ppc64le
python3-debug-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: 337241dd98989e366d6efe947686163d03f9eb9f3ae0560d1299639bad3f2413
python3-idle-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: c7876f69e2823e5bf60a1f9acd27e986c81000049a52974e5cef94361682da4d
python3-test-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: 808de4c6e4ff2494ccf3873bcacdb3ec43c34678b8ff155fd3ca1901531c68d4
python3.9-debuginfo-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: a472b41747934edb8bdf3059a53e0f2b103506db0240635ada2ade750988e4e9
python3.9-debugsource-3.9.25-3.el9_7.2.ppc64le.rpm SHA-256: f655ae77aef5631a894ac4aa2ef397b58227f25674bb564a2a8c7772fdaf85ae

Red Hat CodeReady Linux Builder for ARM 64 9

SRPM
aarch64
python3-debug-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: 8c867283ac5681daed05ee9628588802e323308801aac00e65de4380c975896d
python3-idle-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: dcb9afd23141157f7435753596e00e2464fa20ea604df1d65e1cadf922d3a1e6
python3-test-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: 48a4d3698f960fdf83f038d3c69450fa193d6f28bbf90f236a14cb8e1784bec0
python3.9-debuginfo-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: 76b7583eb2b265f4f2048e3403f0ec66201a3fe0a3d55dceba24e8cd4e23debd
python3.9-debugsource-3.9.25-3.el9_7.2.aarch64.rpm SHA-256: 483a1a04d9869831f642cad3f8f11f4f2a527d8002aefa3f2999e16cb752dcc2

Red Hat CodeReady Linux Builder for IBM z Systems 9

SRPM
s390x
python3-debug-3.9.25-3.el9_7.2.s390x.rpm SHA-256: 8b05feefb49f60b2d59ff22adf8c91189b0be9fe52289a017fe6df7d5e15bc98
python3-idle-3.9.25-3.el9_7.2.s390x.rpm SHA-256: a0e7b2f755e0d7306f62e4b11a3f34be263569df67e948f1f84187bced67c858
python3-test-3.9.25-3.el9_7.2.s390x.rpm SHA-256: 3fafa9080d958acf467ec662602d63b97eda54a0809f1ba7c9e9e5067e61415d
python3.9-debuginfo-3.9.25-3.el9_7.2.s390x.rpm SHA-256: a347900fac19e42934fd4748f1e30444c9e592ceb9e05b3d036aa3fdeed22be2
python3.9-debugsource-3.9.25-3.el9_7.2.s390x.rpm SHA-256: 34f92261e788492b64a3a17481e103b0c6d44caa6d56808001e5d23639915e42

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility