CVE-2026-2297

SourcelessFileLoader does not use io.open_code()

The import hook in CPython that handles legacy *.pyc files (SourcelessFileLoader) is incorrectly handled in FileLoader (a base class) and so does not use io.open_code() to read the .pyc files. sys.audit handlers for this audit event therefore do not fire.


We have discovered 470 live websites that are affected by CVE-2026-2297.

Run a Free Instant Scan




Affected Software

Product  CPython
Category Programming Languages
Vulnerable Domains470 live websites (100% of CPython install base)
Vulnerable Versions
  • from 0 through 3.13.13
  • from 3.14 through 3.14.4
Vulnerable Versions Count72 versions ( 100% of all versions)



Details

  • Published - Mar 4, 2026
  • Updated - Apr 7, 2026

Website Distribution by Country

Number of websites using CVE-2026-2297
United States150 websites



Germany59 websites
Singapore28 websites
India22 websites
France19 websites
Russia15 websites
China13 websites
Brazil11 websites
GB11 websites
Australia10 websites

Website Distribution by TLD

Number of websites using CVE-2026-2297
.com160 websites
.org47 websites
.dk26 websites
.de20 websites
.net19 websites
.nl9 websites
.edu8 websites
.ru8 websites
.fr7 websites
.ch7 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-2297

Top websites that are affected by CVE-2026-2297. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States**,***
*********.com Netherlands***,***
*******.***.org Germany***,***
*****.org Germany***,***
***********.org Australia***,***
****.***********.***.au Australia***,***
*******.org Australia***,***
*****.*****.de Germany***,***
********.***.***.gr Greece***,***
***.********.it Italy***,***
See full domain list

FAQ

A total of 470 websites have been identified as vulnerable to CVE-2026-2297, based on global website indexing conducted by WebTechSurvey.
The CPython is affected by the CVE-2026-2297 vulnerability.
CPython versions up to 3.14.4 are vulnerable to CVE-2026-2297.
CVE-2026-2297 is resolved in version 3.14.4 of CPython.