Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-0672

25
FAUCET Score

CVE-2026-0672 is a medium-severity vulnerability affecting the http.cookies.Morsel component, allowing HTTP header injection through user-controlled cookie values and parameters. This flaw, rated 6.0 on CVSS, has a low attack complexity and requires low privileges, potentially leading to high integrity impacts. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and concern within the security community. The patch addresses this by rejecting all control characters in cookie names, values, and parameters.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 3.10.20CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.11.0, < 3.11.15CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.12.0, < 3.12.13CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.13.0, < 3.13.12CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.14.0, < 3.14.3CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.0MEDIUM

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.40%
Probability of exploitation in next 30 days
EPSS Percentile
32.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0040 is in the 42nd percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (27)

hashicorppatch availablevia llm_extracted
View patch
puppetpatch availablevia llm_extracted
View patch
ubuntupatch availablevia ubuntu_usn
Product: python3.10 (jammy)Fixed in: 3.10.12-1~22.04.16
ubuntupatch availablevia ubuntu_usn
Product: python3.12 (noble)Fixed in: 3.12.3-1ubuntu0.15
ubuntupatch availablevia ubuntu_usn
Product: python3.14 (resolute)Fixed in: 3.14.4-1ubuntu0.1
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python3
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: firefox
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.11
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.12
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python36:3.6/python36
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39-devel:3.9/python39
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: firefox
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.11
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.12
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.14
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-aws-cuda-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-azure-cuda-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-cuda-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI) 3Fixed in: rhelai3/bootc-gcp-cuda-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: firefox
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: python3.12
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: python3.14
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: python
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: firefox

Vendor Advisories (4)

ubuntuUSN-8509-1

Python vulnerabilities

Jul 6, 2026
puppetllm-puppet-6fb008c4e00001d4

USN-8018-3: Python 2.7 vulnerabilities

Mar 19, 2026
hashicorpllm-hashicorp-e1fb8ae78f74759d

USN-8018-3: Python 2.7 vulnerabilities

Mar 19, 2026
redhatCVE-2026-0672Moderate

cpython: Header injection in http.cookies.Morsel in Python

Jan 20, 2026

References

github.com / python/cpython/commit/62700107418eb2cca3fc88da036a243ea975f172
github.com / python/cpython/commit/712452e6f1d4b9f7f8c4c92ebfcaac1705faa440
github.com / python/cpython/commit/7852d72b653fea0199acf5fc2a84f6f8b84eba8d
github.com / python/cpython/commit/918387e4912d12ffc166c8f2a38df92b6ec756ca
github.com / python/cpython/commit/95746b3a13a985787ef53b977129041971ed7f70
github.com / python/cpython/commit/b1869ff648bbee0717221d09e6deff46617f3e85
github.com / python/cpython/issues/143919
github.com / python/cpython/pull/143920
mail.python.org / archives/list/[email protected]/thread/6VFLQQEIX673KXKFUZXCUNE5AZOGZ45M