CVE-2026-3644
EUVD-2026-1248416.03.2026, 18:16
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| python | cpython | 𝑥 < 3.15.0 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration
References