CVE-2026-34444

Name
CVE-2026-34444
Description
Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently applied when attributes are accessed through built-in functions like getattr and setattr. This allows an attacker to bypass the intended restrictions and eventually achieve arbitrary code execution.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/scoder/lupa/security/advisories/GHSA-69v7-xpr6-6gjm

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:scoder:lupa:*:*:*:*:*:python:*:* py3-lupa >= None <= 2.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
py3-lupa edge-community 2.1-r2 Leonardo Arena <rnalrd@alpinelinux.org> possibly vulnerable
py3-lupa edge-community 2.1-r1 Leonardo Arena <rnalrd@alpinelinux.org> possibly vulnerable
py3-lupa 3.23-community 2.1-r1 Leonardo Arena <rnalrd@alpinelinux.org> possibly vulnerable