CVE-2026-3644
Incomplete control character validation in http.cookies
Severity Score
6.0
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().
*Credits:
Stan Ulbrych, Stan Ulbrych, Victor Stinner, Seth Larson, Vyom Yadav
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2026-03-06 CVE Reserved
- 2026-03-16 CVE Published
- 2026-04-07 CVE Updated
- 2026-04-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-116: Improper Encoding or Escaping of Output
CAPEC
References (6)
| URL | Tag | Source |
|---|---|---|
| https://github.com/python/cpython/issues/145599 | Issue Tracking |
| URL | Date | SRC |
|---|
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Python Software Foundation Search vendor "Python Software Foundation" | CPython Search vendor "Python Software Foundation" for product "CPython" | < 3.13.13 Search vendor "Python Software Foundation" for product "CPython" and version " < 3.13.13" | en |
Affected
| ||||||
| Python Software Foundation Search vendor "Python Software Foundation" | CPython Search vendor "Python Software Foundation" for product "CPython" | >= 3.14.0 < 3.14.4 Search vendor "Python Software Foundation" for product "CPython" and version " >= 3.14.0 < 3.14.4" | en |
Affected
| ||||||
