VORANT. Threat Intelligence Research Sign in Create a free account

CPython patches DoS and security bypass flaws

routine vulnerability

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR advisory warns of two CPython vulnerabilities enabling remote denial of service and security policy bypass; patch available.

CERT-FR has published an advisory covering two vulnerabilities in CPython, the reference implementation of the Python programming language. The flaws, tracked as CVE-2026-19445 and CVE-2026-19553, allow an attacker to trigger a remote denial of service and bypass security policy controls. No technical details of the exploitation mechanism are provided in the advisory, which points instead to the official Python security announcements for full details.

Affected systems are any CPython installations that have not applied the latest security patches referenced in the Python Software Foundation's security announcements dated 30 September 2026. There is no indication in this advisory of active exploitation in the wild; this appears to be a standard vulnerability disclosure and patch notification rather than a report of an ongoing campaign.

Defenders running Python-based applications or services should identify CPython versions in use across their estate and apply the vendor-supplied patches referenced in the linked Python security bulletins as soon as feasible, prioritizing internet-facing or otherwise exposed services that could be targeted for denial-of-service disruption.

Mentioned in this report

Vulnerabilities CVE-2026-19445CVE-2026-19553

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1243

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,554 reports from 152 sources, 494 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs