← Back to CVE feed
CVE-2026-1502
Description
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
References
- https://github.com/python/cpython/commit/05ed7ce7ae9e17c23a04085b2539fe6d6d3cef69
- https://github.com/python/cpython/issues/146211
- https://github.com/python/cpython/pull/146212
- https://mail.python.org/archives/list/security-announce@python.org/thread/2IVPAEQWUJBCTQZEJEVTYCIKSMQPGRZ3/
- http://www.openwall.com/lists/oss-security/2026/04/11/4