CVE-2026-0865 describes a vulnerability where user-controlled HTTP header names and values containing newlines can lead to HTTP header injection. While specific affected products are not detailed, the issue stems from improper input validation. This vulnerability carries a CVSS 4.0 score of 5.9 (MEDIUM), indicating a network-based attack with low attack complexity, requiring high privileges to exploit. A successful exploit could lead to high integrity impact, allowing an attacker to manipulate HTTP requests or responses. There is currently no evidence of active exploitation (KEV: No), nor are there public Metasploit or Nuclei modules. However, the vulnerability has garnered significant community attention with 14 mentions and 3 media articles, suggesting awareness and potential for future exploit development.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 3.10.20CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.11.0, < 3.11.15CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.12.0, < 3.12.13CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.13.0, < 3.13.12CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 3.14.0, < 3.14.3CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
USN-8018-3: Python 2.7 vulnerabilities
Mar 19, 2026USN-8018-3: Python 2.7 vulnerabilities
Mar 19, 2026Python regression
Mar 9, 2026cpython: wsgiref.headers.Headers allows header newline injection in Python
Jan 20, 2026