Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4455-1 | python3.9 security update |
Debian DLA |
DLA-4583-1 | python3.9 security update |
Ubuntu USN |
USN-8018-1 | Python vulnerabilities |
Ubuntu USN |
USN-8018-3 | Python 2.7 vulnerabilities |
Mon, 26 Jan 2026 14:45:00 +0000
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 22 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 21 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python
Python cpython |
|
| Vendors & Products |
Python
Python cpython |
Tue, 20 Jan 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 20 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | User-controlled cookie values and parameters can allow injecting HTTP headers. Fix rejects all control characters within cookie names, values, and parameters. | When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters. |
| References |
|
Tue, 20 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | User-controlled cookie values and parameters can allow injecting HTTP headers. Fix rejects all control characters within cookie names, values, and parameters. | |
| Title | Header injection in http.cookies.Morsel | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: PSF
Published:
Updated: 2026-03-03T14:43:20.490Z
Reserved: 2026-01-07T17:08:45.326Z
Link: CVE-2026-0672
Updated: 2026-01-21T15:48:28.463Z
Status : Deferred
Published: 2026-01-20T22:15:52.680
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-0672
OpenCVE Enrichment
Updated: 2026-04-16T18:15:43Z
Debian DLA
Ubuntu USN