CVE-2025-15282
EUVD-2025-20630520.01.2026, 22:15
User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| python | cpython | 𝑥 < 3.10.20 | CNA |
| python | cpython | 3.11.0 ≤ 𝑥 < 3.11.15 | CNA |
| python | cpython | 3.12.0 ≤ 𝑥 < 3.12.13 | CNA |
| python | cpython | 3.13.0 ≤ 𝑥 < 3.13.12 | CNA |
| python | cpython | 3.14.0 ≤ 𝑥 < 3.14.3 | CNA |
Vulnerability Media Exposure
References