[PATCH] [3.10] gh-148169: Fix webbrowser `%action` substitution bypass of dash-prefix...
authorStan Ulbrych <stan@python.org>
Mon, 13 Apr 2026 21:41:53 +0000 (22:41 +0100)
committerArnaud Rebillout <arnaudr@debian.org>
Thu, 14 May 2026 03:00:00 +0000 (10:00 +0700)
commita20e7fcb5b131eb6fe3eda4cde32851e2ae4445f
tree5e29928834f7675ab221163ed201e7062934a242
parentf90f997f1030f5a57e1d9623a504074805fbbe8f
[PATCH] [3.10] gh-148169: Fix webbrowser `%action` substitution bypass of dash-prefix check (GH-148170) (#148521)

(cherry picked from commit d22922c8a7958353689dc4763dd72da2dea03fff)
Origin: upstream, https://github.com/python/cpython/commit/c5767a72838a8dda9d6dc5d3558075b055c56bca

Gbp-Pq: Name CVE-2026-4519-3.patch
Lib/test/test_webbrowser.py
Lib/webbrowser.py
Misc/NEWS.d/next/Security/2026-03-31-09-15-51.gh-issue-148169.EZJzz2.rst [new file with mode: 0644]