vulnti.work

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and …

Info
CVECVE-2026-0864
First seen2026-08-06 01:15 UTC
Disclosed2026-06-23 18:17 UTC
Last updated2026-08-06 02:15 UTC
Channel statusauto

Summary

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD