Base64 decoding stops at first padded quad by default
Published Apr 10, 2026
6.0
MEDIUMCVSS 4.0
EPSS 0.22%
Description
When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "validate=True" to enable stricter processing of base64 data.
Affected products
-
- Version 0StatusaffectedConstraints<3.13.13
- Version 3.14.0StatusaffectedConstraints<3.14.4
- Version 3.15.0a1StatusaffectedConstraints<3.15.0a8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Python Software Foundation | CPython | unaffected |
|
No data.
No data.
Red Hat Hardened Images
python3-11-main-3.11.16-1.1.hum1
Fixed · RHSA-2026:60511
Red Hat Hardened Images
python3-12-main-3.12.13-3.1.hum1
Fixed · RHSA-2026:10118
Red Hat Hardened Images
python3-12-main-3.12.14-1.hum1
Fixed · RHSA-2026:58420
Red Hat Hardened Images
python3-13-main-3.13.13-1.hum1
Fixed · RHSA-2026:7443
Red Hat Hardened Images
python3-14-main-3.14.4-1.hum1
Fixed · RHSA-2026:7661
Red Hat Enterprise Linux 10
python3.12
Not affected
Red Hat Enterprise Linux 10
python3.14
Fix deferred
Red Hat Enterprise Linux 6
python
Not affected
Red Hat Enterprise Linux 7
python
Not affected
Red Hat Enterprise Linux 7
python3
Not affected
Red Hat Enterprise Linux 8
python3
Not affected
Red Hat Enterprise Linux 8
python3.11
Not affected
Red Hat Enterprise Linux 8
python3.12
Not affected
Red Hat Enterprise Linux 8
python36:3.6/python36
Not affected
Red Hat Enterprise Linux 8
python39-devel:3.9/python39
Not affected
Red Hat Enterprise Linux 9
python3.11
Not affected
Red Hat Enterprise Linux 9
python3.12
Not affected
Red Hat Enterprise Linux 9
python3.14
Fix deferred
Red Hat Enterprise Linux 9
python3.9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | python3-11-main-3.11.16-1.1.hum1 | Fixed | RHSA-2026:60511 |
| Red Hat Hardened Images | python3-12-main-3.12.13-3.1.hum1 | Fixed | RHSA-2026:10118 |
| Red Hat Hardened Images | python3-12-main-3.12.14-1.hum1 | Fixed | RHSA-2026:58420 |
| Red Hat Hardened Images | python3-13-main-3.13.13-1.hum1 | Fixed | RHSA-2026:7443 |
| Red Hat Hardened Images | python3-14-main-3.14.4-1.hum1 | Fixed | RHSA-2026:7661 |
| Red Hat Enterprise Linux 10 | python3.12 | Not affected | n/a |
| Red Hat Enterprise Linux 10 | python3.14 | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | python | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3.11 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3.12 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python39-devel:3.9/python39 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.11 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.12 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | python3.14 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | python3.9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2026-3446 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2457410 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-21545 Advisory
- https://github.com/python/cpython/commit/1f9958f909c1b41a4ffc0b613ef8ec8fa5e7c474 patch
- https://github.com/python/cpython/commit/4561f6418a691b3e89aef0901f53fe0dfb7f7c0e patch
- https://github.com/python/cpython/commit/e31c55121620189a0d1a07b689762d8ca9c1b7fa patch
- https://github.com/python/cpython/issues/145264 issue-tracking
- https://github.com/python/cpython/pull/145267 patch
- https://mail.python.org/archives/list/security-announce@python.org/thread/F5ZT5ICGJ6CKXVUJ34YBVY7WOZ5SHG53/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-3446
- https://www.cve.org/CVERecord?id=CVE-2026-3446
Change history (0)
No recorded changes yet.