# CPython patches DoS and security bypass flaws

Published: 2026-10-01 · Severity: routine
Canonical: https://vorant.io/reports/4992801a-3630-50fd-a64a-5a64042b0343/cpython-patches-dos-and-security-bypass-flaws

> CERT-FR advisory warns of two CPython vulnerabilities enabling remote denial of service and security policy bypass; patch available.

CERT-FR has published an advisory covering two vulnerabilities in CPython, the reference implementation of the Python programming language. The flaws, tracked as CVE-2026-19445 and CVE-2026-19553, allow an attacker to trigger a remote denial of service and bypass security policy controls. No technical details of the exploitation mechanism are provided in the advisory, which points instead to the official Python security announcements for full details.

Affected systems are any CPython installations that have not applied the latest security patches referenced in the Python Software Foundation's security announcements dated 30 September 2026. There is no indication in this advisory of active exploitation in the wild; this appears to be a standard vulnerability disclosure and patch notification rather than a report of an ongoing campaign.

Defenders running Python-based applications or services should identify CPython versions in use across their estate and apply the vendor-supplied patches referenced in the linked Python security bulletins as soon as feasible, prioritizing internet-facing or otherwise exposed services that could be targeted for denial-of-service disruption.

## Mentioned in this report

- Vulnerabilities: CVE-2026-19445, CVE-2026-19553

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1243

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4992801a-3630-50fd-a64a-5a64042b0343/cpython-patches-dos-and-security-bypass-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
