CVE-2026-0865: Python Software Foundation Cpython
Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.
User-controlled header names and values containing newlines can allow injecting HTTP headers.
Affected products
- Python Software Foundation Cpython: before 3.10.20 (fixed in 3.10.20); from 3.11.0, before 3.11.15 (fixed in 3.11.15); from 3.12.0, before 3.12.13 (fixed in 3.12.13); from 3.13.0, before 3.13.12 (fixed in 3.13.12); from 3.14.0, before 3.14.3 (fixed in 3.14.3); from 3.15.0a1, before 3.15.0a6 (fixed in 3.15.0a6)
Published 2026-01-20. Last modified 2026-06-17.