Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.3
CVE-2026-7210: Python 3.13 on Debian 13 can let attackers run code
CVE-2026-7210 · published 1 day ago
Summary
The Python 3.13 package shipped with Debian 13 (including related packages such as python‑min, libpython, and pypy3) contains a flaw that could let a malicious user execute arbitrary commands on the system. This could lead to unauthorized access or data loss. Install the latest updated Python packages from the Debian repository as soon as possible to close the gap.
What to do
- Update bellsoft python3 to version 3.11.15-r2.
- Update bellsoft python3 to version 3.12.13-r2.
- Update bellsoft python3 to version 3.14.3-r2.
- Update debian python3.13 to version 3.13.14-1.
- Update debian python3.14 to version 3.14.6-1.
- Update python to version 3.14.6.
- Update python-min to version 3.14.6.
- Update libpython to version 3.14.6.
- Update debian rootio-python3.9 to version 3.9.2-1+deb11u7.root.io.13.
- Update debian rootio-python3.13 to version 3.13.5-2+deb13u2.root.io.20.
- Update debian rootio-python3.13 to version 3.13.5-2+deb13u3.aikido.21.
- Update alpine python3 to version 3.14.7-r0.
- Update alpine python3 to version 3.12.13-r00071.
- Update alpine rootio-python3 to version 3.12.13-r00071.
- Update alpine python3 to version 3.12.13-r00073.
- Update alpine rootio-python3 to version 3.12.13-r00073.
- Update alpine python3 to version 3.12.13-r00074.
- Update alpine rootio-python3 to version 3.12.13-r00074.
- Update debian rootio-python3.9 to version 3.9.2-1+deb11u7.root.io.16.
- Update debian rootio-python3.9 to version 3.9.2-1+deb11u7.aikido.17.
- Update debian rootio-python3.11 to version 3.11.2-6+deb12u7.root.io.34.
- Update debian python3.11 to version 3.11.2-6+deb12u8.aikido.36.
- Update debian rootio-python3.11 to version 3.11.2-6+deb12u8.aikido.36.
- Update debian rootio-python3.13 to version 3.13.5-2+deb13u2.root.io.19.
- Update python3.9 to version 3.9.2-1+deb11u7.aikido.21.
- Update python3-defaults to version 3.9.2-3.aikido.2.
- Update rootio-python3.9 to version 3.9.2-1+deb11u7.aikido.21.
- Update rootio-python3-defaults to version 3.9.2-3.aikido.2.
- Update python3.11 to version 3.11.2-6+deb12u8.aikido.38.
- Update python3-defaults to version 3.11.2-1.aikido.1.
- Update rootio-python3.11 to version 3.11.2-6+deb12u8.aikido.38.
- Update rootio-python3-defaults to version 3.11.2-1.aikido.1.
- Update python3.9 to version 3.9.2-1+deb11u7.aikido.22.
- Update rootio-python3.9 to version 3.9.2-1+deb11u7.aikido.22.
- Update python3 to version 3.12.13-r00075.
- Update rootio-python3 to version 3.12.13-r00075.
- Update python3.13 to version 3.13.5-2+deb13u5.aikido.25.
- Update rootio-python3.13 to version 3.13.5-2+deb13u5.aikido.25.
- Update python3.13 to version 3.13.5-2+deb13u5.aikido.26.
- Update rootio-python3.13 to version 3.13.5-2+deb13u5.aikido.26.
- Update libexpat_project libexpat to version 2.8.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | python | python |
< 3.15.0 < 3.13.14 >= 3.14.0, < 3.14.6 3.15.0 cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| Bitnami | – | python |
>= 3.14.0, < 3.14.6 Fix: upgrade to 3.14.6
|
| Bitnami | – | python-min |
>= 3.14.0, < 3.14.6 Fix: upgrade to 3.14.6
|
| Bitnami | – | libpython |
>= 3.14.0, < 3.14.6 Fix: upgrade to 3.14.6
|
| Debian:14 | debian | pypy3 | All versions |
| Debian:11 | debian | python2.7 | All versions |
| Debian:12 | debian | python3.11 | All versions |
| Debian:13 | debian | python3.13 | All versions |
| – | libexpat_project | libexpat |
< 2.8.0 cpe:2.3:a:libexpat_project:libexpat:*:*:*:*:*:*:*:* |
| Ubuntu:Pro:14.04:LTS | canonical | python2.7 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | python2.7 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | python3.6 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | python3.7 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | python3.8 | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | python3.8 | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | python2.7 | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | python3.9 | All versions |
| Ubuntu:22.04:LTS | canonical | python3.10 | All versions |
| Alpaquita:23 | bellsoft | python3 |
>= 3.11.3-r0, < 3.11.15-r2 Fix: upgrade to 3.11.15-r2
|
| Alpaquita:25 | bellsoft | python3 |
>= 3.12.10-r1, < 3.12.13-r2 Fix: upgrade to 3.12.13-r2
|
| Alpaquita:stream | bellsoft | python3 |
>= 3.11.4-r0, < 3.14.3-r2 Fix: upgrade to 3.14.3-r2
|
| Ubuntu:Pro:14.04:LTS | canonical | python3.4 | All versions |
| Ubuntu:Pro:14.04:LTS | canonical | python3.5 | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | python2.7 | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | python3.5 | All versions |
| Ubuntu:Pro:22.04:LTS | canonical | python2.7 | All versions |
| Ubuntu:Pro:22.04:LTS | canonical | python3.11 | All versions |
| Ubuntu:24.04:LTS | canonical | python3.12 | All versions |
| Ubuntu:25.10 | canonical | python3.13 | All versions |
| Ubuntu:25.10 | canonical | python3.14 | All versions |
| Ubuntu:26.04:LTS | canonical | python3.14 | All versions |
| Debian:11 | debian | pypy3 | All versions |
| Debian:12 | debian | pypy3 | All versions |
| Debian:13 | debian | pypy3 | All versions |
| Debian:14 | debian | python3.13 |
< 3.13.14-1 Fix: upgrade to 3.13.14-1
|
| Debian:14 | debian | python3.14 |
< 3.14.6-1 Fix: upgrade to 3.14.6-1
|
| Debian:11 | debian | python3.9 | All versions |
| BellSoft Hardened Containers:25 | bellsoft | python3 |
>= 3.12.10-r1, < 3.12.13-r2 Fix: upgrade to 3.12.13-r2
|
| BellSoft Hardened Containers:stream | bellsoft | python3 |
>= 3.11.4-r0, < 3.14.3-r2 Fix: upgrade to 3.14.3-r2
|
| Root:Debian:11 | debian | rootio-python3.9 |
< 3.9.2-1+deb11u7.root.io.13 < 3.9.2-1+deb11u7.root.io.16 < 3.9.2-1+deb11u7.aikido.17 Fix: upgrade to 3.9.2-1+deb11u7.root.io.13
|
| Root:Debian:13 | debian | rootio-python3.13 |
< 3.13.5-2+deb13u2.root.io.20 < 3.13.5-2+deb13u3.aikido.21 < 3.13.5-2+deb13u2.root.io.19 Fix: upgrade to 3.13.5-2+deb13u2.root.io.20
|
| – | python software foundation | cpython |
< 3.13.14 < 3.11.16 |
| Alpine:v3.24 | alpine | python3 |
< 3.14.7-r0 Fix: upgrade to 3.14.7-r0
|
| BellSoft Hardened Containers:23 | bellsoft | python3 |
>= 3.11.3-r0, < 3.11.15-r2 Fix: upgrade to 3.11.15-r2
|
| Root:Alpine:3.20 | alpine | python3 |
< 3.12.13-r00071 < 3.12.13-r00073 < 3.12.13-r00074 Fix: upgrade to 3.12.13-r00071
|
| Root:Alpine:3.20 | alpine | rootio-python3 |
< 3.12.13-r00071 < 3.12.13-r00073 < 3.12.13-r00074 Fix: upgrade to 3.12.13-r00071
|
| Root:Debian:12 | debian | rootio-python3.11 |
< 3.11.2-6+deb12u7.root.io.34 < 3.11.2-6+deb12u8.aikido.36 Fix: upgrade to 3.11.2-6+deb12u7.root.io.34
|
| Root:Debian:12 | debian | python3.11 |
< 3.11.2-6+deb12u8.aikido.36 Fix: upgrade to 3.11.2-6+deb12u8.aikido.36
|
| Root:Debian:11 | – | python3.9 |
< 3.9.2-1+deb11u7.aikido.21 < 3.9.2-1+deb11u7.aikido.22 Fix: upgrade to 3.9.2-1+deb11u7.aikido.21
|
| Root:Debian:11 | – | python3-defaults |
< 3.9.2-3.aikido.2 Fix: upgrade to 3.9.2-3.aikido.2
|
Showing 50 of 60. Show the rest
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:Debian:11 | – | rootio-python3.9 |
< 3.9.2-1+deb11u7.aikido.21 < 3.9.2-1+deb11u7.aikido.22 Fix: upgrade to 3.9.2-1+deb11u7.aikido.21
|
| Root:Debian:11 | – | rootio-python3-defaults |
< 3.9.2-3.aikido.2 Fix: upgrade to 3.9.2-3.aikido.2
|
| Root:Debian:12 | – | python3.11 |
< 3.11.2-6+deb12u8.aikido.38 Fix: upgrade to 3.11.2-6+deb12u8.aikido.38
|
| Root:Debian:12 | – | python3-defaults |
< 3.11.2-1.aikido.1 Fix: upgrade to 3.11.2-1.aikido.1
|
| Root:Debian:12 | – | rootio-python3.11 |
< 3.11.2-6+deb12u8.aikido.38 Fix: upgrade to 3.11.2-6+deb12u8.aikido.38
|
| Root:Debian:12 | – | rootio-python3-defaults |
< 3.11.2-1.aikido.1 Fix: upgrade to 3.11.2-1.aikido.1
|
| Root:Alpine:3.20 | – | python3 |
< 3.12.13-r00075 Fix: upgrade to 3.12.13-r00075
|
| Root:Alpine:3.20 | – | rootio-python3 |
< 3.12.13-r00075 Fix: upgrade to 3.12.13-r00075
|
| Root:Debian:13 | – | python3.13 |
< 3.13.5-2+deb13u5.aikido.25 < 3.13.5-2+deb13u5.aikido.26 Fix: upgrade to 3.13.5-2+deb13u5.aikido.25
|
| Root:Debian:13 | – | rootio-python3.13 |
< 3.13.5-2+deb13u5.aikido.25 < 3.13.5-2+deb13u5.aikido.26 Fix: upgrade to 3.13.5-2+deb13u5.aikido.25
|
Original advisory text
CVE-2026-7210 in python3.13 - Patched by Root
Root has patched CVE-2026-7210 in the python3.13 package for Root:Debian:13. Multiple fixed versions available.
References
- https://security-tracker.debian.org/tracker/CVE-2026-7210 Vendor Advisory
- https://docs.bell-sw.com/security/cves/CVE-2026-7210 Vendor Advisory
- https://github.com/python/cpython/commit/ea70712d1a8508e14e9677d44f838dab04dc028... URL
- https://github.com/python/cpython/commit/eeea765cb9d8f1fc3d8918b272ac3c477983f27... Patch
- https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145... Patch
- https://github.com/python/cpython/pull/149023 Patch
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/7xxx/CVE-2026-7210.j... Vendor Advisory
- https://github.com/python/cpython Product
- https://security.alpinelinux.org/vuln/CVE-2026-7210 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-7210 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-7210 Third Party Advisory
- http://www.openwall.com/lists/oss-security/2026/05/11/8 Vendor Advisory
- https://github.com/python/cpython/issues/149018 Third Party Advisory
- https://mail.python.org/archives/list/[email protected]/thread/PNY5OM... Vendor Advisory
- https://github.com/python/cpython/commit/3573b3b1ecbd99030a0b18658e1bfece771b256... Patch
- https://nvd.nist.gov/vuln/detail/CVE-2026-7210 URL
- https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e... Patch
- https://github.com/python/cpython/commit/cbaecf9f16da611a646d507c1cbca265c588fc5... URL
- https://github.com/python/cpython/commit/e37df2a6a71d6538698e2d3188a7c345b827640... URL
- http://www.openwall.com/lists/oss-security/2026/05/11/13 Vendor Advisory
Severity
7.3
High
CVSS 4.0: 6.3 (NVD)
CVSS 4.0: 7.3 (OSV)
CVSS 3.1: 9.8 (OSV)
Exploitation
EPSS 1%
Type
CWE-331Insufficient Entropy
Timeline
Published24 Sep 2026
Updated25 Sep 2026
First seen11 May 2026
Sources
BELL-CVE-2026-7210 · OSV
DEBIAN-CVE-2026-7210 · OSV
UBUNTU-CVE-2026-7210 · OSV
CVE-2026-7210 · OSV
CVE-2026-7210 · NVD
BIT-libpython-2026-7210 · OSV
BIT-python-2026-7210 · OSV
PSF-2026-23 · OSV
BIT-python-min-2026-7210 · OSV
CVE-2026-7210 · MITRE
ALPINE-CVE-2026-7210 · OSV
Track software like this
Free during beta