Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-1502

27
FAUCET Score

CVE-2026-1502 is a vulnerability affecting HTTP client proxy tunnel implementations that fail to properly reject carriage return/line feed (CR/LF) bytes in tunnel headers and host fields. This input validation flaw could potentially allow attackers to inject arbitrary content into HTTP communications through proxy tunnels. The specific products and versions impacted require further investigation based on individual vendor patch releases. The vulnerability carries a FAUCET Risk Score of 42.0/100, indicating moderate concern, though a CVSS score has not been assigned. The attack vector appears to be network-based and likely requires low to moderate complexity for exploitation. The potential impact involves HTTP request smuggling or header injection attacks that could lead to cache poisoning, session hijacking, or unauthorized access to backend services. Currently, this vulnerability shows minimal exploitation activity. It is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on security hotlists. The EPSS score of 0.0006 reflects a very low probability of exploitation in the wild. Public exploit code availability is not evident at this time, and community attention remains limited.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, < 3.13.14CPE match
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.7MEDIUM

CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
HIGH
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.56%
Probability of exploitation in next 30 days
EPSS Percentile
43.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0056 is in the 71st percentile among its peer group of 4,937 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia msrc
Product: azl3 python3 3.12.9-11 on Azure Linux 3.0Fixed in: 3.12.9-11
microsoftpatch availablevia msrc
Product: azl3 python3 3.12.9-10 on Azure Linux 3.0Fixed in: 3.12.9-11
microsoftpatch availablevia msrc
Product: 21379-17084Fixed in: 3.12.9-11
microsoftpatch availablevia msrc
Product: 21100-17084Fixed in: 3.12.9-11
ubuntupatch availablevia ubuntu_usn
Product: python3.10 (jammy)Fixed in: 3.10.12-1~22.04.16
ubuntupatch availablevia ubuntu_usn
Product: python3.12 (noble)Fixed in: 3.12.3-1ubuntu0.15
ubuntupatch availablevia ubuntu_usn
Product: python3.14 (resolute)Fixed in: 3.14.4-1ubuntu0.1

Vendor Advisories (2)

ubuntuUSN-8509-1

Python vulnerabilities

Jul 6, 2026
microsoft2026-Apr/CVE-2026-1502Moderate

HTTP client proxy tunnel headers not validated for CR/LF

Apr 14, 2026

References

openwall.com / lists/oss-security/2026/04/11/4
github.com / python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69
github.com / python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53
github.com / python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3e
github.com / python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8dd
github.com / python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2ed
github.com / python/cpython/commit/c00c386faa579ad71196d33408644478488e43ec
github.com / python/cpython/issues/146211
github.com / python/cpython/pull/146212
mail.python.org / archives/list/[email protected]/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3