CVE-2026-1502: Python Software Foundation Cpython
Medium severity, CVSS 5.7. EPSS: 0.6% chance of exploitation in the next 30 days.
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
Affected products
- Python Software Foundation Cpython: before 3.10.21 (fixed in 3.10.21); from 3.11.0, before 3.11.16 (fixed in 3.11.16); from 3.12.0, before 3.12.14 (fixed in 3.12.14); from 3.13.0, before 3.13.14 (fixed in 3.13.14); from 3.14.0a1, before 3.14.5rc1 (fixed in 3.14.5rc1); from 3.15.0a1, before 3.15.0b1 (fixed in 3.15.0b1)
Published 2026-04-10. Last modified 2026-08-13.