CVE-2026-1502
published 2026-04-10CVE-2026-1502: CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
PriorityP429medium5.7CVSS 4.0
AVNACLATPPRHUIPVCNVIHVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.56%
43.0th percentile
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| python_software_foundation | cpython | < 3.13.14 | 3.13.14 |
| python_software_foundation | cpython | >= 3.14.0a1 < 3.14.5rc1 | 3.14.5rc1 |
| python_software_foundation | cpython | >= 3.15.0a1 < 3.15.0b1 | 3.15.0b1 |
| ubuntu | python3.10 | — | — |
| ubuntu | python3.12 | — | — |
| ubuntu | python3.14 | — | — |
CVSS provenance
nvdv4.05.7MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.7MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Python CPython up to 3.14.x HTTP Client Proxy Tunnel crlf injection (ID 146211 / EUVD-2026-21519)
vuldb·2026-04-10·CVSS 5.7
CVE-2026-1502 [MEDIUM] Python CPython up to 3.14.x HTTP Client Proxy Tunnel crlf injection (ID 146211 / EUVD-2026-21519)
A vulnerability marked as problematic has been reported in Python CPython up to 3.14.x. The impacted element is an unknown function of the component HTTP Client Proxy Tunnel Handler. Performing a manipulation results in crlf injection.
This vulnerability was named CVE-2026-1502. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
GHSA-hjxq-7w9q-2jw6: CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host
ghsa_unreviewed·2026-04-10
CVE-2026-1502 [MEDIUM] GHSA-hjxq-7w9q-2jw6: CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 3.3
CVE-2026-9669 [LOW] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly normalized paths in the tarfile
module. An attacker could possibly use this issue to bypass path
restrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (CVE-2025-13462)
It was discovered that Python's HTMLParser incorrectly handled certain
malformed HTML input. An attacker could possibly use this issue to cause
Python to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-69534)
It was discovered that Python's email module incorrectly quoted newlines
in headers. An attacker could possibly use this issue to inject arbitrary
email headers. This issue only affected Ubuntu 22.04 L
Red Hat
python: Python: HTTP header injection via CR/LF in proxy tunnel headers
vendor_redhat·2026-04-10·CVSS 5.7
CVE-2026-1502 [MEDIUM] CWE-93 python: Python: HTTP header injection via CR/LF in proxy tunnel headers
python: Python: HTTP header injection via CR/LF in proxy tunnel headers
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
A flaw was found in Python. This vulnerability allows for the injection of extra information into HTTP communication. Specifically, the system does not properly prevent special characters (carriage return and line feed) from being included in HTTP client proxy tunnel headers or host fields.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: python3.12 (Red Hat Enterprise Linux 10) - Fix deferred
Package: python3.14 (Red Hat Enterprise Linux
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-46297 kernel: net: libwx: use request_irq for VF misc interrupt
bugzilla·2026-06-08
CVE-2026-46297 CVE-2026-46297 kernel: net: libwx: use request_irq for VF misc interrupt
CVE-2026-46297 kernel: net: libwx: use request_irq for VF misc interrupt
In the Linux kernel, the following vulnerability has been resolved:
net: libwx: use request_irq for VF misc interrupt
Currently, request_threaded_irq() is used with a primary handler but a
NULL threaded handler, while also setting the IRQF_ONESHOT flag. This
specific combination triggers a WARNING since the commit aef30c8d569c
("genirq: Warn about using IRQF_ONESHOT without a threaded handler").
WARNING: kernel/irq/manage.c:1502 at __setup_irq+0x4fa/0x760
Fix the issue by switching to request_irq(), which is the appropriate
interface or a non-threaded interrupt handler, and removing the
unnecessary IRQF_ONESHOT flag.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026060858-CVE-2026-4
Bugzilla
CVE-2026-1502 mingw-python3: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
bugzilla·2026-04-13·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 mingw-python3: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
CVE-2026-1502 mingw-python3: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-1502 python3.6: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
bugzilla·2026-04-13·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 python3.6: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
CVE-2026-1502 python3.6: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-1502 python3.10: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
bugzilla·2026-04-13·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 python3.10: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
CVE-2026-1502 python3.10: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-1502 python3.9: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
bugzilla·2026-04-13·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 python3.9: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
CVE-2026-1502 python3.9: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-1502 python3.15: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
bugzilla·2026-04-13·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 python3.15: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
CVE-2026-1502 python3.15: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-1502 asahi-installer: Python: HTTP header injection via CR/LF in proxy tunnel headers [epel-all]
bugzilla·2026-04-13·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 asahi-installer: Python: HTTP header injection via CR/LF in proxy tunnel headers [epel-all]
CVE-2026-1502 asahi-installer: Python: HTTP header injection via CR/LF in proxy tunnel headers [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-1502 python3.12: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
bugzilla·2026-04-13·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 python3.12: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
CVE-2026-1502 python3.12: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-1502 python3.11: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
bugzilla·2026-04-13·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 python3.11: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
CVE-2026-1502 python3.11: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-1502 python3.14: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
bugzilla·2026-04-13·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 python3.14: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
CVE-2026-1502 python3.14: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-1502 asahi-installer: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
bugzilla·2026-04-13·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 asahi-installer: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
CVE-2026-1502 asahi-installer: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-1502 python3.13: Python: HTTP header injection via CR/LF in proxy tunnel headers [epel-all]
bugzilla·2026-04-13·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 python3.13: Python: HTTP header injection via CR/LF in proxy tunnel headers [epel-all]
CVE-2026-1502 python3.13: Python: HTTP header injection via CR/LF in proxy tunnel headers [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-1502 python3.13: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
bugzilla·2026-04-13·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 python3.13: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
CVE-2026-1502 python3.13: Python: HTTP header injection via CR/LF in proxy tunnel headers [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-1502 python: Python: HTTP header injection via CR/LF in proxy tunnel headers
bugzilla·2026-04-10·CVSS 5.7
CVE-2026-1502 [MEDIUM] CVE-2026-1502 python: Python: HTTP header injection via CR/LF in proxy tunnel headers
CVE-2026-1502 python: Python: HTTP header injection via CR/LF in proxy tunnel headers
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69https://github.com/python/cpython/commit/56b7100b04e44ea27989242b176beb8f016b2c53https://github.com/python/cpython/commit/58703ec1bdd1eb075e8b01a0c427683ce594dd3ehttps://github.com/python/cpython/commit/9e071c9b28c17f347f81b388a003d4eeb3c7a8ddhttps://github.com/python/cpython/commit/b1cf9016335cb637c5a425032e8274a224f4b2edhttps://github.com/python/cpython/commit/c00c386faa579ad71196d33408644478488e43echttps://github.com/python/cpython/issues/146211https://github.com/python/cpython/pull/146212https://mail.python.org/archives/list/[email protected]/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/http://www.openwall.com/lists/oss-security/2026/04/11/4
2026-04-10
Published