CVE-2025-15282 is a medium-severity vulnerability in urllib.request.DataHandler that allows attackers to inject headers into data URLs through newlines in the mediatype field. While no specific affected products are listed, it impacts Python environments utilizing this component. The attack vector is network-based with low attack complexity, and successful exploitation could lead to information integrity issues. There is currently no public exploit code available, nor is it listed in CISA's KEV catalog, but it has garnered significant community discussion and media coverage, indicating awareness and potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 3.10.20CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.11.0, < 3.11.15CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.12.0, < 3.12.13CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.13.0, < 3.13.12CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.14.0, < 3.14.3CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.