Skip to content

[3.10] gh-145506: Fixes CVE-2026-2297 by ensuring SourcelessFileLoader uses io.open_code (GH-145507)#145516

Merged
pablogsal merged 3 commits intopython:3.10from
miss-islington:backport-a51b1b5-3.10
Apr 30, 2026
Merged

[3.10] gh-145506: Fixes CVE-2026-2297 by ensuring SourcelessFileLoader uses io.open_code (GH-145507)#145516
pablogsal merged 3 commits intopython:3.10from
miss-islington:backport-a51b1b5-3.10

Conversation

@miss-islington
Copy link
Copy Markdown
Contributor

@miss-islington miss-islington commented Mar 4, 2026

… uses io.open_code (pythonGH-145507)

(cherry picked from commit a51b1b5)

Co-authored-by: Steve Dower <steve.dower@python.org>
@StanFromIreland
Copy link
Copy Markdown
Member

Check generated files was failing in CI so I ran make regen-all and pushed.

Comment thread Misc/NEWS.d/next/Security/2026-03-04-18-59-17.gh-issue-145506.6hwvEh.rst Outdated
The `:cve:` role is not available on this branch.
@pablogsal pablogsal merged commit 876858c into python:3.10 Apr 30, 2026
15 checks passed
@miss-islington miss-islington deleted the backport-a51b1b5-3.10 branch April 30, 2026 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type-security A security issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants