CVE-2026-1502 is a vulnerability affecting HTTP client proxy tunnel implementations that fail to properly reject carriage return/line feed (CR/LF) bytes in tunnel headers and host fields. This input validation flaw could potentially allow attackers to inject arbitrary content into HTTP communications through proxy tunnels. The specific products and versions impacted require further investigation based on individual vendor patch releases. The vulnerability carries a FAUCET Risk Score of 42.0/100, indicating moderate concern, though a CVSS score has not been assigned. The attack vector appears to be network-based and likely requires low to moderate complexity for exploitation. The potential impact involves HTTP request smuggling or header injection attacks that could lead to cache poisoning, session hijacking, or unauthorized access to backend services. Currently, this vulnerability shows minimal exploitation activity. It is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on security hotlists. The EPSS score of 0.0006 reflects a very low probability of exploitation in the wild. Public exploit code availability is not evident at this time, and community attention remains limited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 3.13.14CPE match | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.