CVE-2026-0865
EUVD-2026-352020.01.2026, 22:15
User-controlled header names and values containing newlines can allow injecting HTTP headers.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| python | cpython | 𝑥 < 3.10.20 | CNA |
| python | cpython | 3.11.0 ≤ 𝑥 < 3.11.15 | CNA |
| python | cpython | 3.12.0 ≤ 𝑥 < 3.12.13 | CNA |
| python | cpython | 3.13.0 ≤ 𝑥 < 3.13.12 | CNA |
| python | cpython | 3.14.0 ≤ 𝑥 < 3.14.3 | CNA |
Vulnerability Media Exposure
References