Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-15282

Опубликовано: 20 янв. 2026
Источник: debian
EPSS Низкий

Описание

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14fixed3.14.3-1package
python3.13fixed3.13.12-1package
python3.13fixed3.13.5-2+deb13u1trixiepackage
python3.11removedpackage
python3.11fixed3.11.2-6+deb12u7bookwormpackage
python3.9removedpackage
pypy3fixed7.3.21+dfsg-1package
pypy3no-dsatrixiepackage
pypy3no-dsabookwormpackage
pypy3postponedbullseyepackage
python2.7not-affectedpackage

Примечания

  • https://github.com/python/cpython/issues/143925

  • https://github.com/python/cpython/pull/143926

  • https://mail.python.org/archives/list/security-announce@python.org/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/

  • https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f (main)

  • https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0 (3.14 branch)

  • https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a (3.13 branch)

  • https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80 (3.11 branch)

  • https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38 (3.10-branch)

EPSS

Процентиль: 39%
0.0048
Низкий

Связанные уязвимости

ubuntu
6 месяцев назад

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.

CVSS3: 4.8
redhat
6 месяцев назад

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.

nvd
6 месяцев назад

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.

github
6 месяцев назад

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.

CVSS3: 7.7
fstec
7 месяцев назад

Уязвимость компонента urllib.request.DataHandler интерпретатора языка программирования Python, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 39%
0.0048
Низкий