Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:9260 - Security Advisory
Issued:
2026-04-21
Updated:
2026-04-21

RHSA-2026:9260 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: python3.11 security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for python3.11 is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • python: Python: Command-line option injection in webbrowser.open() via crafted URLs (CVE-2026-4519)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x

Fixes

  • BZ - 2449649 - CVE-2026-4519 python: Python: Command-line option injection in webbrowser.open() via crafted URLs

CVEs

  • CVE-2026-4519

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
python3.11-3.11.2-2.el9_2.11.src.rpm SHA-256: 4fe888f476f0741dd5e71a5fd26f382747df98cb367721ff582bea44eb34c07c
x86_64
python3.11-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: 9411b21f456f89408836322aed518df2b2b890e8c411d2c92cc0697b0726d1a0
python3.11-debuginfo-3.11.2-2.el9_2.11.i686.rpm SHA-256: d10c7bd11a45d8c156a6f6497060e654f76076a625ae6b53d32db09a6454eb2e
python3.11-debuginfo-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: 733c3df1f30e5e2441bb7125711387f38d703269a30b1a852314f2619020f98c
python3.11-debugsource-3.11.2-2.el9_2.11.i686.rpm SHA-256: 476037606735a4efa8518a412690b38cdc69404cd0d336d8469601bc8a2a9aca
python3.11-debugsource-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: 7df8d10691959639f91691f719489534c414579903e6d19a5a2daa6010aa44de
python3.11-devel-3.11.2-2.el9_2.11.i686.rpm SHA-256: 8a518146aba3f3a78ba89b3740223661614d72af79f4c707d608debbae48c1de
python3.11-devel-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: e1b66d11f98e1c6b504f4418680c27ce1299bc0003c27eafc9f75bc755590c3f
python3.11-libs-3.11.2-2.el9_2.11.i686.rpm SHA-256: 97a4a9a31c7354bb29c3058e5d60d6c2eb44a49d70fe8ecdea49e6152d5c5aa2
python3.11-libs-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: d51a4c5ce771f4c1e3d610d0dc93030391aff1ee912cf9c1f1cb3d0dfbe0325d
python3.11-tkinter-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: ec188165f5a077b8c2115bc186fd4c6814a4d771a04f79517fb9728b83bdd69c

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
python3.11-3.11.2-2.el9_2.11.src.rpm SHA-256: 4fe888f476f0741dd5e71a5fd26f382747df98cb367721ff582bea44eb34c07c
ppc64le
python3.11-3.11.2-2.el9_2.11.ppc64le.rpm SHA-256: 1ca7681ecb5c40f979aadfffb71fae0fd34d174726d5d35818a10bd36a9e9c56
python3.11-debuginfo-3.11.2-2.el9_2.11.ppc64le.rpm SHA-256: 89835f7d34d77c759d2809f287ff6e4d97ad16f76e8343133fcff8f4d2fefe06
python3.11-debugsource-3.11.2-2.el9_2.11.ppc64le.rpm SHA-256: 34b11ceaf27addd51e6b1bab08a3677b8eb210dfd2c5770aebc18b5d7b5c19b8
python3.11-devel-3.11.2-2.el9_2.11.ppc64le.rpm SHA-256: 8549727c382f3416cfd5ec3d92137018695764f1337ee43d277ffa65c488da68
python3.11-libs-3.11.2-2.el9_2.11.ppc64le.rpm SHA-256: 1395630634d2d79e1dba19fd8bcf6816965add80eddd560135e5cca4f4edef6f
python3.11-tkinter-3.11.2-2.el9_2.11.ppc64le.rpm SHA-256: e2f0a5ed751291f92d761bc5e8bb30d3037d6b6da89d260b455830915e69a0ee

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
python3.11-3.11.2-2.el9_2.11.src.rpm SHA-256: 4fe888f476f0741dd5e71a5fd26f382747df98cb367721ff582bea44eb34c07c
x86_64
python3.11-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: 9411b21f456f89408836322aed518df2b2b890e8c411d2c92cc0697b0726d1a0
python3.11-debuginfo-3.11.2-2.el9_2.11.i686.rpm SHA-256: d10c7bd11a45d8c156a6f6497060e654f76076a625ae6b53d32db09a6454eb2e
python3.11-debuginfo-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: 733c3df1f30e5e2441bb7125711387f38d703269a30b1a852314f2619020f98c
python3.11-debugsource-3.11.2-2.el9_2.11.i686.rpm SHA-256: 476037606735a4efa8518a412690b38cdc69404cd0d336d8469601bc8a2a9aca
python3.11-debugsource-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: 7df8d10691959639f91691f719489534c414579903e6d19a5a2daa6010aa44de
python3.11-devel-3.11.2-2.el9_2.11.i686.rpm SHA-256: 8a518146aba3f3a78ba89b3740223661614d72af79f4c707d608debbae48c1de
python3.11-devel-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: e1b66d11f98e1c6b504f4418680c27ce1299bc0003c27eafc9f75bc755590c3f
python3.11-libs-3.11.2-2.el9_2.11.i686.rpm SHA-256: 97a4a9a31c7354bb29c3058e5d60d6c2eb44a49d70fe8ecdea49e6152d5c5aa2
python3.11-libs-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: d51a4c5ce771f4c1e3d610d0dc93030391aff1ee912cf9c1f1cb3d0dfbe0325d
python3.11-tkinter-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: ec188165f5a077b8c2115bc186fd4c6814a4d771a04f79517fb9728b83bdd69c

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
python3.11-3.11.2-2.el9_2.11.src.rpm SHA-256: 4fe888f476f0741dd5e71a5fd26f382747df98cb367721ff582bea44eb34c07c
aarch64
python3.11-3.11.2-2.el9_2.11.aarch64.rpm SHA-256: de3c96888488b52f46c62e3085ea0da129684153e27c2ff98f9426f82c02c3a2
python3.11-debuginfo-3.11.2-2.el9_2.11.aarch64.rpm SHA-256: f72494abbd7786b524e56c144e5b3692acaeb6c19fbe5c746d30fb35eed183a3
python3.11-debugsource-3.11.2-2.el9_2.11.aarch64.rpm SHA-256: 37a8d7220e0acc2fd37e7ce894cee75ba77ec139ff116ffb3a0a8651c3cf2280
python3.11-devel-3.11.2-2.el9_2.11.aarch64.rpm SHA-256: 8d7a033a960b016c52e097a9eb060816d64d43946b638e69e33b8d503f20664b
python3.11-libs-3.11.2-2.el9_2.11.aarch64.rpm SHA-256: d27be51afc7ba06f71f5b06fa1b993440802100ff8ffca7fe5166bd7726b6eff
python3.11-tkinter-3.11.2-2.el9_2.11.aarch64.rpm SHA-256: 1aba69f579f5cb5affedac69090ab88f6c7a56439e6b82f9653a92ff902adaf1

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
python3.11-3.11.2-2.el9_2.11.src.rpm SHA-256: 4fe888f476f0741dd5e71a5fd26f382747df98cb367721ff582bea44eb34c07c
s390x
python3.11-3.11.2-2.el9_2.11.s390x.rpm SHA-256: d50e7a4a1805af97f4bb3e271ab9fc4616d3f5cd7e56f8b86013bd916fa9e5ab
python3.11-debuginfo-3.11.2-2.el9_2.11.s390x.rpm SHA-256: 71b07d7f126748d734c7affc6853149ae7f19c56eabe08c7d8b370a75e2dbc31
python3.11-debugsource-3.11.2-2.el9_2.11.s390x.rpm SHA-256: ea2791a6ac2ea44b36b091f8230f57e502aa7301d25603a9d94f9338cfc17ed1
python3.11-devel-3.11.2-2.el9_2.11.s390x.rpm SHA-256: e14784baa1e0b75be2eae57d3bad65364fb78a6b1c48e45f6c9584105f38e767
python3.11-libs-3.11.2-2.el9_2.11.s390x.rpm SHA-256: deef9d8f51595f2d388393df3426c9a44104cfcd652d671c80db3bd21b3c67f6
python3.11-tkinter-3.11.2-2.el9_2.11.s390x.rpm SHA-256: 7d62c3f8e20077e1d0149868ab23fe6754b205a046604a2050ccb12741c8f5fb

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2

SRPM
python3.11-3.11.2-2.el9_2.11.src.rpm SHA-256: 4fe888f476f0741dd5e71a5fd26f382747df98cb367721ff582bea44eb34c07c
x86_64
python3.11-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: 9411b21f456f89408836322aed518df2b2b890e8c411d2c92cc0697b0726d1a0
python3.11-debuginfo-3.11.2-2.el9_2.11.i686.rpm SHA-256: d10c7bd11a45d8c156a6f6497060e654f76076a625ae6b53d32db09a6454eb2e
python3.11-debuginfo-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: 733c3df1f30e5e2441bb7125711387f38d703269a30b1a852314f2619020f98c
python3.11-debugsource-3.11.2-2.el9_2.11.i686.rpm SHA-256: 476037606735a4efa8518a412690b38cdc69404cd0d336d8469601bc8a2a9aca
python3.11-debugsource-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: 7df8d10691959639f91691f719489534c414579903e6d19a5a2daa6010aa44de
python3.11-devel-3.11.2-2.el9_2.11.i686.rpm SHA-256: 8a518146aba3f3a78ba89b3740223661614d72af79f4c707d608debbae48c1de
python3.11-devel-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: e1b66d11f98e1c6b504f4418680c27ce1299bc0003c27eafc9f75bc755590c3f
python3.11-libs-3.11.2-2.el9_2.11.i686.rpm SHA-256: 97a4a9a31c7354bb29c3058e5d60d6c2eb44a49d70fe8ecdea49e6152d5c5aa2
python3.11-libs-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: d51a4c5ce771f4c1e3d610d0dc93030391aff1ee912cf9c1f1cb3d0dfbe0325d
python3.11-tkinter-3.11.2-2.el9_2.11.x86_64.rpm SHA-256: ec188165f5a077b8c2115bc186fd4c6814a4d771a04f79517fb9728b83bdd69c

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2

SRPM
python3.11-3.11.2-2.el9_2.11.src.rpm SHA-256: 4fe888f476f0741dd5e71a5fd26f382747df98cb367721ff582bea44eb34c07c
aarch64
python3.11-3.11.2-2.el9_2.11.aarch64.rpm SHA-256: de3c96888488b52f46c62e3085ea0da129684153e27c2ff98f9426f82c02c3a2
python3.11-debuginfo-3.11.2-2.el9_2.11.aarch64.rpm SHA-256: f72494abbd7786b524e56c144e5b3692acaeb6c19fbe5c746d30fb35eed183a3
python3.11-debugsource-3.11.2-2.el9_2.11.aarch64.rpm SHA-256: 37a8d7220e0acc2fd37e7ce894cee75ba77ec139ff116ffb3a0a8651c3cf2280
python3.11-devel-3.11.2-2.el9_2.11.aarch64.rpm SHA-256: 8d7a033a960b016c52e097a9eb060816d64d43946b638e69e33b8d503f20664b
python3.11-libs-3.11.2-2.el9_2.11.aarch64.rpm SHA-256: d27be51afc7ba06f71f5b06fa1b993440802100ff8ffca7fe5166bd7726b6eff
python3.11-tkinter-3.11.2-2.el9_2.11.aarch64.rpm SHA-256: 1aba69f579f5cb5affedac69090ab88f6c7a56439e6b82f9653a92ff902adaf1

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2

SRPM
python3.11-3.11.2-2.el9_2.11.src.rpm SHA-256: 4fe888f476f0741dd5e71a5fd26f382747df98cb367721ff582bea44eb34c07c
ppc64le
python3.11-3.11.2-2.el9_2.11.ppc64le.rpm SHA-256: 1ca7681ecb5c40f979aadfffb71fae0fd34d174726d5d35818a10bd36a9e9c56
python3.11-debuginfo-3.11.2-2.el9_2.11.ppc64le.rpm SHA-256: 89835f7d34d77c759d2809f287ff6e4d97ad16f76e8343133fcff8f4d2fefe06
python3.11-debugsource-3.11.2-2.el9_2.11.ppc64le.rpm SHA-256: 34b11ceaf27addd51e6b1bab08a3677b8eb210dfd2c5770aebc18b5d7b5c19b8
python3.11-devel-3.11.2-2.el9_2.11.ppc64le.rpm SHA-256: 8549727c382f3416cfd5ec3d92137018695764f1337ee43d277ffa65c488da68
python3.11-libs-3.11.2-2.el9_2.11.ppc64le.rpm SHA-256: 1395630634d2d79e1dba19fd8bcf6816965add80eddd560135e5cca4f4edef6f
python3.11-tkinter-3.11.2-2.el9_2.11.ppc64le.rpm SHA-256: e2f0a5ed751291f92d761bc5e8bb30d3037d6b6da89d260b455830915e69a0ee

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2

SRPM
python3.11-3.11.2-2.el9_2.11.src.rpm SHA-256: 4fe888f476f0741dd5e71a5fd26f382747df98cb367721ff582bea44eb34c07c
s390x
python3.11-3.11.2-2.el9_2.11.s390x.rpm SHA-256: d50e7a4a1805af97f4bb3e271ab9fc4616d3f5cd7e56f8b86013bd916fa9e5ab
python3.11-debuginfo-3.11.2-2.el9_2.11.s390x.rpm SHA-256: 71b07d7f126748d734c7affc6853149ae7f19c56eabe08c7d8b370a75e2dbc31
python3.11-debugsource-3.11.2-2.el9_2.11.s390x.rpm SHA-256: ea2791a6ac2ea44b36b091f8230f57e502aa7301d25603a9d94f9338cfc17ed1
python3.11-devel-3.11.2-2.el9_2.11.s390x.rpm SHA-256: e14784baa1e0b75be2eae57d3bad65364fb78a6b1c48e45f6c9584105f38e767
python3.11-libs-3.11.2-2.el9_2.11.s390x.rpm SHA-256: deef9d8f51595f2d388393df3426c9a44104cfcd652d671c80db3bd21b3c67f6
python3.11-tkinter-3.11.2-2.el9_2.11.s390x.rpm SHA-256: 7d62c3f8e20077e1d0149868ab23fe6754b205a046604a2050ccb12741c8f5fb

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility