Логотип exploitDog
bind:CVE-2026-3644
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-3644

Количество 6

Количество 6

ubuntu логотип

CVE-2026-3644

10 дней назад

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

EPSS: Низкий
redhat логотип

CVE-2026-3644

10 дней назад

A control character validation flaw has been discovered in the Python http.cookie module. The Morsel.update(), |= operator, and unpickling paths were not patched to resolve CVE-2026-0672, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-3644

10 дней назад

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

EPSS: Низкий
msrc логотип

CVE-2026-3644

8 дней назад

Incomplete control character validation in http.cookies

EPSS: Низкий
debian логотип

CVE-2026-3644

10 дней назад

The fix for CVE-2026-0672, which rejected control characters in http.c ...

EPSS: Низкий
github логотип

GHSA-vf33-88pf-hwp3

10 дней назад

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

0%
Низкий
10 дней назад
redhat логотип
CVE-2026-3644

A control character validation flaw has been discovered in the Python http.cookie module. The Morsel.update(), |= operator, and unpickling paths were not patched to resolve CVE-2026-0672, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS3: 5.4
0%
Низкий
10 дней назад
nvd логотип
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

0%
Низкий
10 дней назад
msrc логотип
CVE-2026-3644

Incomplete control character validation in http.cookies

0%
Низкий
8 дней назад
debian логотип
CVE-2026-3644

The fix for CVE-2026-0672, which rejected control characters in http.c ...

0%
Низкий
10 дней назад
github логотип
GHSA-vf33-88pf-hwp3

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

0%
Низкий
10 дней назад

Уязвимостей на страницу