Skip to content
October 6, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • Python Patches python.org API Authentication Bypass Flaw
  • Vulnerability Report

Python Patches python.org API Authentication Bypass Flaw

Do Son June 26, 2026 2 minutes read
0
python.org authentication bypass affecting Python release metadata and download API
Add Daily CyberSecurity as a preferred source on Google

TL;DR

The Python Software Foundation fixed a python.org authentication bypass on February 24, 2026. The flaw sat in the release management API. It let a request pass an admin username with any API key and gain admin rights.

Route critical CVEs to one Slack channel, everything else to another.

Try Team free for 14 days →

Why this python.org authentication bypass matters

python.org serves download links to millions of developers. An attacker could not alter release files in place. However, they could change the URLs shown on the downloads page. That includes links to Sigstore and PGP verification material. As a result, the bug touched the software supply chain.

How the attack works

The release management API mixed two login modes. A guest request could supply an admin username with an arbitrary API key. The server then processed that request with admin privileges. DEVCORE researcher Splitline Ng reported the issue on February 23, 2026.

Affected systems

The flaw lived in the python.org web codebase, not in CPython itself. It had existed since 2014. Therefore, no Python package or local install needs patching. The fix runs entirely on Python’s own servers.

Exploitation status

The reporter supplied a working proof-of-concept to the security team. Still, audits of logs and database backups found no sign of abuse. As the team explains in its official advisory, the many downstream tools that verify signatures make silent exploitation unlikely.

Patch and hardening

Python deployed the fix within 48 hours of the report. The team also blocked URLs that do not start with python.org’s HTTPS domain. In addition, log retention grew from 3 to 30 days. Trail of Bits later audited the release process. Users should keep verifying Sigstore and PGP materials before trusting any build.

Related coverage

  • Values Over Cash: Python Foundation Rejects $1.5M US Grant Over Anti-DEI Clause
  • GitLab Patches High-Severity Flaws: Update Now to Prevent XSS and Account Takeover
  • Critical Apache WSS4J Vulnerabilities Fixed in Update
  • Critical Cisco RCE Flaw (CVE-2025-20265, CVSS 10): Unauthenticated Attackers Can Hijack Firewalls
  • FortiMail Path Traversal Flaw CVE-2026-104286 Exploited in the Wild
  • Helm Flaw (CVE-2025-53547): Local Code Execution via Malicious Chart.yaml & Symlinks
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Authentication Bypass DEVCORE PSF Python python.org release metadata Supply Chain Security Trail of Bits

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105080CVSS 9.4
    In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program...
    📅 Updated: Oct 6, 2026
  • CVE-2026-105863CVSS 9.2
    Payload is a free and open source headless content management system. In versions after 3.0.0 and before 3.90.0,...
    📅 Updated: Oct 6, 2026
  • CVE-2026-104849CVSS 9.5
    Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied...
    📅 Updated: Oct 6, 2026
  • CVE-2026-105859CVSS 9.8
    Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions...
    📅 Updated: Oct 6, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    📅 Updated: Oct 6, 2026
  • CVE-2026-16346CVSS 9.9
    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands...
    📅 Updated: Oct 6, 2026
  • CVE-2026-84075CVSS 9.9
    IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication...
    📅 Updated: Oct 6, 2026
  • CVE-2026-84073CVSS 9.1
    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to...
    📅 Updated: Oct 6, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.