#1147615 urwid: CVE-2026-9323

Package:
src:urwid
Source:
src:urwid
Submitter:
Moritz Mühlenhoff
Date:
2026-09-13 21:01:02 UTC
Severity:
normal
Tags:
#1147615#5
Date:
2026-09-13 20:58:58 UTC
From:
To:
Hi,

The following vulnerability was published for urwid.

CVE-2026-9323[0]:
| The urwid web display backend (urwid/display/web.py) generates web
| session identifiers (urwid_id) in Screen.start() by concatenating
| two random.randrange(10**9) calls that use Python's Mersenne Twister
| PRNG, which is not cryptographically secure. Each call consumes
| approximately 30 bits of PRNG state, and the Mersenne Twister
| internal state is approximately 19,937 bits, so an attacker who
| observes approximately 334 session IDs (for example via the X-Urwid-
| ID HTTP response header) can fully reconstruct the internal state
| and predict all past and future session IDs (Path B). The same
| identifier is also used as the filename of a FIFO created in the
| world-listable /tmp directory (for example
| /tmp/urwid375487765176907690.in), so any local user on the host can
| list /tmp to enumerate active session tokens directly (Path A). With
| a valid session ID, an attacker can read the victim's terminal
| screen via the polling endpoint, inject keystrokes into the victim's
| session (yielding OS-level code execution with the session owner's
| privileges if the session runs a shell), and inject exit sequences
| or flood the FIFO to terminate or crash the session. A prior Bandit
| S311 warning on this usage was suppressed with # noqa: S311 rather
| than fixed

https://github.com/urwid/urwid/security/advisories/GHSA-rjwp-g85x-gmjv
https://github.com/urwid/urwid/pull/1128

Fixed by: https://github.com/urwid/urwid/commit/24acd12f0d0598036d0d577f2ee63e4a27b4a3d9 (4.0.2)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-9323
https://www.cve.org/CVERecord?id=CVE-2026-9323

Please adjust the affected versions in the BTS as needed.