CVE-2026-0672: Python Software Foundation Cpython

Medium severity, CVSS 6.0. EPSS: 0.5% chance of exploitation in the next 30 days.

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.

Affected products

  • Python Software Foundation Cpython: before 3.10.20 (fixed in 3.10.20); from 3.11.0, before 3.11.15 (fixed in 3.11.15); from 3.12.0, before 3.12.13 (fixed in 3.12.13); from 3.13.0, before 3.13.12 (fixed in 3.13.12); from 3.14.0, before 3.14.3 (fixed in 3.14.3); from 3.15.0a1, before 3.15.0a6 (fixed in 3.15.0a6)

Published 2026-01-20. Last modified 2026-06-17.