Bug 2431374 (CVE-2026-0672) - CVE-2026-0672 cpython: Header injection in http.cookies.Morsel in Python
Summary: CVE-2026-0672 cpython: Header injection in http.cookies.Morsel in Python
Keywords:
Status: NEW
Alias: CVE-2026-0672
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2431749 2431751 2431753 2431757 2431762 2431765 2431770 2431787 2431792 2431794 2431799 2431803 2431809 2431814 2431817 2431820 2431824 2431828 2431833 2431837 2431840 2431844 2431846
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-01-20 22:02 UTC by OSIDB Bzimport
Modified: 2026-01-21 20:34 UTC (History)
15 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-01-20 22:02:40 UTC
User-controlled cookie values and parameters can allow injecting HTTP headers. Fix rejects all control characters within cookie names, values, and parameters.


Note You need to log in before you can comment on or make changes to this bug.