CVE-2026-0672
Header injection in http.cookies.Morsel
When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
Python Software Foundation · CPython¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://github.com/python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172https://github.com/python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440https://github.com/python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8dhttps://github.com/python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756cahttps://github.com/python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70https://github.com/python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85https://github.com/python/cpython/issues/143919https://github.com/python/cpython/pull/143920https://mail.python.org/archives/list/security-announce@python.org/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M/