# CERT-FR Advisory: CPython Data Integrity Flaw

Published: 2026-09-30 · Severity: routine
Canonical: https://vorant.io/reports/4a8d50d9-4968-5bbe-9e60-8bbcf9942c4c/cert-fr-advisory-cpython-data-integrity-flaw

> A CPython vulnerability (CVE-2026-12345) allows an attacker to compromise data integrity; patch to the latest secure version.

CERT-FR has issued an advisory regarding a vulnerability in CPython, the reference implementation of the Python programming language. The flaw, tracked as CVE-2026-12345 and detailed in Python Security Response Team advisory PSF-2026-42, allows an attacker to cause a data integrity compromise on affected systems. Systems running CPython without the latest security patch are affected.

No evidence of active exploitation is mentioned in the bulletin. CERT-FR recommends organizations consult the official Python security bulletin for patch details and apply the update promptly. This is a routine vendor patch advisory rather than a report of in-the-wild attack activity.

## Mentioned in this report

- Vulnerabilities: CVE-2026-12345

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1239

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4a8d50d9-4968-5bbe-9e60-8bbcf9942c4c/cert-fr-advisory-cpython-data-integrity-flaw.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
