chiprook
← Security
SecuritySeptember 19, 2026, 20:31

CVE-2026-63349: Privilege Dropping Bypass and DoS in AnyIO Subprocess Module

In the AnyIO async Python library (versions 4.14.0 and 4.14.1 on POSIX), a typo in a variable assignment leaves child processes with extra parent groups, bypassing privilege dropping. CVE-2026-63349 has a CVSS score of 7.0 and is fixed in version 4.14.2.

CVE-2026-63349: Privilege Dropping Bypass and DoS in AnyIO Subprocess Module
#AnyIO#Python
Read next
Security

Kaspersky uncovers malware campaign spread via movie torrents

Security

Z.ai silently uploaded devs' local data: 313MB and 564 upload attempts

Security

Samsung and LG to remove botnet apps from smart TV stores

Security

CrowdSec confirms source code stolen in supply chain attack