RHSA-2026:58954HighCVSS 8.1

Red Hat Security Advisory: python-urwid security update

Published
August 24, 2026
Last Modified
August 24, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-9323 — urwid: Urwid: Predictable session IDs lead to remote code execution and information disclosure

🎯 Affected products14

  • Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python-urwid-0:2.1.2-4.el9_2.1.src as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python-urwid-debugsource-0:2.1.2-4.el9_2.1.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python-urwid-debugsource-0:2.1.2-4.el9_2.1.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python-urwid-debugsource-0:2.1.2-4.el9_2.1.s390x as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python-urwid-debugsource-0:2.1.2-4.el9_2.1.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python3-urwid-0:2.1.2-4.el9_2.1.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python3-urwid-0:2.1.2-4.el9_2.1.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python3-urwid-0:2.1.2-4.el9_2.1.s390x as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python3-urwid-0:2.1.2-4.el9_2.1.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python3-urwid-debuginfo-0:2.1.2-4.el9_2.1.aarch64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python3-urwid-debuginfo-0:2.1.2-4.el9_2.1.ppc64le as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python3-urwid-debuginfo-0:2.1.2-4.el9_2.1.s390x as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)
  • python3-urwid-debuginfo-0:2.1.2-4.el9_2.1.x86_64 as a component of Red Hat Enterprise Linux BaseOS E4S (v.9.2)

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this vulnerability, it is recommended to disable the urwid web display backend if its functionality is not essential for your environment. If the urwid web display backend must remain active, restrict network access to the service to trusted clients only by implementing appropriate firewall rules. This will limit the exposure to remote attackers attempting to reconstruct session IDs. Additionally, ensure that local system configurations prevent unauthorized access to temporary files, which could otherwise allow local users to enumerate active session tokens. Any changes to service configurations may require a service restart to take effect.

🔗 References (4)