Affected packages
- python3.14— before 3.14.7-2.el10_2
- python3.14-debug— before 3.14.7-2.el10_2
- python3.14-devel— before 3.14.7-2.el10_2
- python3.14-freethreading— before 3.14.7-2.el10_2
- python3.14-freethreading-debug— before 3.14.7-2.el10_2
- python3.14-freethreading-devel— before 3.14.7-2.el10_2
- python3.14-freethreading-idle— before 3.14.7-2.el10_2
- python3.14-freethreading-libs— before 3.14.7-2.el10_2
- python3.14-freethreading-test— before 3.14.7-2.el10_2
- python3.14-freethreading-tkinter— before 3.14.7-2.el10_2
- python3.14-idle— before 3.14.7-2.el10_2
- python3.14-libs— before 3.14.7-2.el10_2
- python3.14-test— before 3.14.7-2.el10_2
- python3.14-tkinter— before 3.14.7-2.el10_2
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://access.redhat.com/errata/RHSA-2026:58928
- https://access.redhat.com/security/cve/CVE-2026-11940
- https://bugzilla.redhat.com/2491848
- https://errata.almalinux.org/10/ALSA-2026-58928.html
Structured record: https://osv.dev/vulnerability/ALSA-2026:58928
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta