CVE-2026-3644
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and u
CVSS
7.5
High
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Published: Mar 16, 2026 · Last modified: Jun 30, 2026 · CWE-20 · CWE-116
0.4%EPSS · 30 days0.4%
2026-06-302026-07-19
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().
- github.comhttps://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8
- github.comhttps://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4
- github.comhttps://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd
- github.comhttps://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd
- github.comhttps://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef
- github.comhttps://github.com/python/cpython/issues/145599
- github.comhttps://github.com/python/cpython/pull/145600
- mail.python.orghttps://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-341978.8 HIG99.9%
KEV—80Apache ActiveMQ Improper Input Validation Vulnerability5dCVE-2026-125699.8 CRI66.0%
KEV—70PTC Windchill and FlexPLM Improper Input Validation Vulnerability20dCVE-2025-607877.2 HIG97.0%
——29MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin access to achieve code execution when Motion is restarted.15dCVE-2017-149197.5 HIG94.3%
——28Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.6dCVE-2026-482849.6 CRI94.1%
——28ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.5dCVE-2022-457258.8 HIG93.4%
——28Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request11d