CVE-2026-2297
EUVD-2026-949804.03.2026, 23:16
The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| python | cpython | 𝑥 < 3.13.13 | CNA |
| python | cpython | 3.14.0 ≤ 𝑥 < 3.14.4 | CNA |
Common Weakness Enumeration
Vulnerability Media Exposure
References