Bug 2457409 (CVE-2026-1502)
| Summary: | CVE-2026-1502 python: Python: HTTP header injection via CR/LF in proxy tunnel headers | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | bbrownin, dfreiber, drow, jburrell, rhel-process-autobot, vkumar, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Python. This vulnerability allows for the injection of extra information into HTTP communication. Specifically, the system does not properly prevent special characters (carriage return and line feed) from being included in HTTP client proxy tunnel headers or host fields.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2457936, 2457937, 2457938, 2457940, 2457943, 2457946, 2457947, 2457939, 2457941, 2457942, 2457944, 2457945 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-04-10 19:01:31 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:10950 https://access.redhat.com/errata/RHSA-2026:10950 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19019 https://access.redhat.com/errata/RHSA-2026:19019 This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:19064 https://access.redhat.com/errata/RHSA-2026:19064 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19176 https://access.redhat.com/errata/RHSA-2026:19176 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:19177 https://access.redhat.com/errata/RHSA-2026:19177 |