CVE-2026-0672 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control character…
Medium CVSS: 6.0

CVE-2026-0672

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.
Vendor
-
Product
-
CWE
CWE-93
Yayın Tarihi
2026-01-20 22:15:52
Güncelleme
2026-01-26 15:16:07
Source Identifier
cna@python.org
KEV Date Added
-

Kategoriler

Referanslar