Microsoft Security Response Center guidance
CBL-Mariner Releases Release Notes
Vendor-listed releases
- 3.12.9-14
Vulnerability intelligence
CVE-2026-2297 and is rated Medium severity with a CVSS score of 5.7. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases Release Notes
The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.