Incorrect Control Flow Scoping in once - CVE-2026-3449
Published: August 18, 2026
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to Incorrect Control Flow Scoping in promise resolving when AbortSignal option is used. The Promise remains in a permanently pending state after the signal is aborted, causing any await or .then() usage to hang indefinitely. A local user can trigger the vulnerability to cause a control-flow leak that can lead to stalled requests, blocked workers, or degraded application availability.
Affected software
Fedora
python-jupytext
IBM QRadar Data Synchronization App
How to mitigate CVE-2026-3449
python-jupytext - addressed in versions 1.19.1-4.fc42, 1.19.1-4.fc43, 1.19.1-4.fc44
IBM QRadar Data Synchronization App - update to 4.0.0