CVE-2026-0672
Severity CVSS v4.0:
MEDIUM
Type:
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')
Publication date:
20/01/2026
Last modified:
20/01/2026
Description
When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.
Impact
Base Score 4.0
6.00
Severity 4.0
MEDIUM



