CVE-2026-1502
MEDIUMHTTP client proxy tunnel headers not validated for CR/LF
Title source: cnaDescription
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
Scores
CVSS v4
5.7
EPSS
0.0006
EPSS Percentile
18.8%
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Details
Status
published
Products (1)
Python Software Foundation/CPython
< 3.15.0
Published
Apr 10, 2026
Tracked Since
Apr 11, 2026