CVE-2025-15282: Python Software Foundation Cpython
Medium severity, CVSS 6.0. EPSS: 0.5% chance of exploitation in the next 30 days.
User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.
Affected products
- Python Software Foundation Cpython: before 3.10.20 (fixed in 3.10.20); from 3.11.0, before 3.11.15 (fixed in 3.11.15); from 3.12.0, before 3.12.13 (fixed in 3.12.13); from 3.13.0, before 3.13.12 (fixed in 3.13.12); from 3.14.0, before 3.14.3 (fixed in 3.14.3); from 3.15.0a1, before 3.15.0a6 (fixed in 3.15.0a6)
Published 2026-01-20. Last modified 2026-06-17.