Back

MEDIUM

Base64 decoding stops at first padded quad by default

Published Apr 10, 2026

Description

When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "validate=True" to enable stricter processing of base64 data.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PSF
Published Apr 10, 2026
Updated Apr 13, 2026
Reserved Mar 2, 2026
CISA Vulnrichment
Updated Apr 13, 2026
NVD
Status Awaiting Analysis
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 10, 2026
ENISA EUVD
Assigner PSF
Published Apr 10, 2026
Updated Apr 13, 2026
Exploited since n/a
EUVD-2026-21545