CVE-2025-15282

Severity CVSS v4.0:
MEDIUM
Type:
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')
Publication date:
20/01/2026
Last modified:
26/01/2026

Description

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.