HackTesting
HomeArticlesTagsContact

CVE-2026-1502

CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.

Credits

senseicat
Seth Larson

References

https://github.com/python/cpython/pull/146212
https://github.com/python/cpython/issues/146211
https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/
https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69
https://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed
Published
Apr 10, 2026 17:54:44 UTC
Updated
May 10, 2026 20:05:37 UTC
Reserved
Jan 27, 2026 19:10:37 UTC
  • Home
  • Contact Us
  • Recently Updated CVEs
  • Articles
  • Tags
  • RSS Feed
  • Privacy Policy
© 2026 HackTesting. All rights reserved.