NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-0864
Summary

When using the "configparser" module to write configuration files
containing multi-line text values with carriage return characters (\r) the
resulting file could be injected with unexpected keys and values if the
attacker controls the written value.

Publication Date June 24, 2026, 3:17 a.m.
Registration Date June 27, 2026, 4:14 a.m.
Last Update June 26, 2026, 4:51 a.m.
Related information, measures and tools
Common Vulnerabilities List