CVE-2026-3644Incomplete Filtering of Special Elements in Software Foundation Cpython

Severity
6.0MEDIUMNVD
EPSS
0.1%
top 70.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 16

Description

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Packages1 packages

CVEListV5python_software_foundation/cpython3.14.03.14.4+2

🔴Vulnerability Details

4
CVEList
Incomplete control character validation in http.cookies2026-03-16
GHSA
GHSA-vf33-88pf-hwp3: The fix for CVE-2026-0672, which rejected control characters in http2026-03-16
OSV
CVE-2026-3644: The fix for CVE-2026-0672, which rejected control characters in http2026-03-16
GHSA
pypdf possibly has long runtimes for malformed FlateDecode streams2026-02-18

📋Vendor Advisories

3
Red Hat
cpython: Incomplete control character validation in http.cookies2026-03-16
Microsoft
Incomplete control character validation in http.cookies2026-03-10
Debian
CVE-2026-3644: python3.11 - The fix for CVE-2026-0672, which rejected control characters in http.cookies.Mor...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-3644 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

5
Bugzilla
CVE-2026-3644 python3.14: Incomplete control character validation in http.cookies [fedora-all]2026-03-16
Bugzilla
CVE-2026-3644 mingw-python3: Incomplete control character validation in http.cookies [fedora-all]2026-03-16
Bugzilla
CVE-2026-3644 python3.15: Incomplete control character validation in http.cookies [fedora-all]2026-03-16
Bugzilla
CVE-2026-3644 python3.13: Incomplete control character validation in http.cookies [fedora-all]2026-03-16
Bugzilla
CVE-2026-3644 cpython: Incomplete control character validation in http.cookies2026-03-16
CVE-2026-3644 — MEDIUM severity | cvebase