Medium severityOSV Advisory· Published Jan 20, 2026· Updated Apr 15, 2026
CVE-2026-0672
CVE-2026-0672
Description
When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.
Affected products
1- Range: v0.9.8, v0.9.9, v1.0.1, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- github.com/python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172nvd
- github.com/python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440nvd
- github.com/python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8dnvd
- github.com/python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756canvd
- github.com/python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70nvd
- github.com/python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85nvd
- github.com/python/cpython/issues/143919nvd
- github.com/python/cpython/pull/143920nvd
- mail.python.org/archives/list/security-announce@python.org/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M/nvd
News mentions
0No linked articles in our index yet.