PT-2026-25789 · Python · Cpython

Seth Larson

+3

·

Published

2026-03-16

·

Updated

2026-03-16

·

CVE-2026-3644

CVSS v4.0
6.0
VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js output() lacked the output validation applied to BaseCookie.output().

Fix

RCE

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2026-3644

Affected Products

Cpython