Python Software Foundation Mitigated API authentication bypass for python.org download metadata
News Source : Blogspot.com
News Summary
- On February 23rd 2026, Splitline Ng from the DEVCORE Research Team reported to the Python Security Response Team (PSRT) an authentication bypass vulnerability.
- By supplying an admin username with an arbitrary API key the request was processed with admin privileges.
- If exploited, this would have allowed an attacker to modify Python release and file metadata that affects what URLs users are offered when visiting python.org/downloads.
- There is no evidence this vulnerability was exploited after auditing logs and database backups.
This post is a crosspost from the Python Insider Blog.
Never miss a story from us, subscribe to our newsletter