Skip to content

[3.11] gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545)#151568

Open
miss-islington wants to merge 1 commit into
python:3.11from
miss-islington:backport-9e863fa-3.11
Open

[3.11] gh-151544: Fixes CVE-2026-12003 by removing the fallback to %VPATH%/Modules/Setup.local for discovering sources in getpath.py (GH-151545)#151568
miss-islington wants to merge 1 commit into
python:3.11from
miss-islington:backport-9e863fa-3.11

Conversation

@miss-islington

@miss-islington miss-islington commented Jun 16, 2026

Copy link
Copy Markdown
Contributor

…ATH%/Modules/Setup.local for discovering sources in getpath.py (pythonGH-151545)

(cherry picked from commit 9e863fa)

Co-authored-by: Steve Dower <steve.dower@python.org>
@zooba

zooba commented Jun 17, 2026

Copy link
Copy Markdown
Member

The macOS failure appears unrelated and is not fixed by rerunning, so I'm leaving it.

@pablogsal this is ready to merge into 3.11, unless you really want the WASI build updated (like for 3.14, except the change will be different because 3.11 pins an even older version that will have even less support for the path fixups necessary...)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants