CVE-2026-1502
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
10/04/2026
Last modified:
21/04/2026
Description
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
Impact
Base Score 4.0
5.70
Severity 4.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69
- https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed
- https://github.com/python/cpython/issues/146211
- https://github.com/python/cpython/pull/146212
- https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/
- http://www.openwall.com/lists/oss-security/2026/04/11/4



