Critical python.org Vulnerability Allowed Attackers to Forge Admin-Level API Requests

A critical authentication bypass vulnerability in the python.org release management API could have allowed attackers to impersonate administrators, potentially redirecting millions of users to malicious download URLs. The flaw, responsibly disclosed on February 23, 2026, by Splitline Ng of the DEVCORE Research Team, was patched within 48 hours of the initial report. The vulnerability resided […]

The post Critical python.org Vulnerability Allowed Attackers to Forge Admin-Level API Requests appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: