Red Hat Security Advisory: python-urwid security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-9323 — urwid: Urwid: Predictable session IDs lead to remote code execution and information disclosure
🎯 Affected products14
- Red Hat Enterprise Linux BaseOS (v. 10)
- python-urwid-0:2.5.3-4.el10_2.5.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- python-urwid-debugsource-0:2.5.3-4.el10_2.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- python-urwid-debugsource-0:2.5.3-4.el10_2.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- python-urwid-debugsource-0:2.5.3-4.el10_2.5.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- python-urwid-debugsource-0:2.5.3-4.el10_2.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- python3-urwid-0:2.5.3-4.el10_2.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- python3-urwid-0:2.5.3-4.el10_2.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- python3-urwid-0:2.5.3-4.el10_2.5.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- python3-urwid-0:2.5.3-4.el10_2.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- python3-urwid-debuginfo-0:2.5.3-4.el10_2.5.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- python3-urwid-debuginfo-0:2.5.3-4.el10_2.5.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- python3-urwid-debuginfo-0:2.5.3-4.el10_2.5.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
- python3-urwid-debuginfo-0:2.5.3-4.el10_2.5.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this vulnerability, it is recommended to disable the urwid web display backend if its functionality is not essential for your environment. If the urwid web display backend must remain active, restrict network access to the service to trusted clients only by implementing appropriate firewall rules. This will limit the exposure to remote attackers attempting to reconstruct session IDs. Additionally, ensure that local system configurations prevent unauthorized access to temporary files, which could otherwise allow local users to enumerate active session tokens. Any changes to service configurations may require a service restart to take effect.