CVE-2026-0672Patch

LOWCVSS 6.0 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-13); latest day: 1
  • 8 total mentions across 7 days

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-02-20: 1Mentions · 2026-02-25: 1Mentions · 2026-03-07: 1Mentions · 2026-03-13: 2Mentions · 2026-03-17: 1Mentions · 2026-03-19: 1Mentions · 2026-03-25: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-13: 2Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-13: 2Technical Details · 2026-03-17: 1Technical Details · 2026-03-25: 102-2002-2503-0703-1303-1703-1903-25
Signal classification2 categories
Patch
675.0%
Disclosure
225.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-201
Patch1
2026-02-251
Patch1
2026-03-071
Disclosure1
2026-03-132
Patch2
2026-03-171
Patch1
2026-03-191
Patch1
2026-03-251
Disclosure1
Full discourse8 posts
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    SUSE #Python 3.11.15 security advisory (SUSE-SU-2026:20796-1) is out. Rating: Important. 8 CVEs addressed including CVE-2026-0672 (CVSS 8.7) for control character injection in cookies. Read more: 👉 https://tinyurl.com/28c9s5sk #SUSE https://t.co/9VWk0CQNIc

    Post summary

    The text announces a SUSE Python 3.11.15 security advisory covering CVE‑2026‑0672, highlighting a control character injection flaw in cookies with CVSS 8.7, and indicates that a vendor patch has been released.

    0001048
    1.5K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-0672 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/443 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The message indicates that CVE‑2026‑0672 is no longer present in recent AWS Lambda base image scans, suggesting it has been mitigated or is no longer a concern, but no additional patch details or exploitation information are provided.

    0000037
    32 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-3644 The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not pat… https://www.cve.org/CVERecord?id=CVE-2026-3644

    Post summary

    The note indicates that the earlier patch for CVE‑2026‑0672 was incomplete, leaving the Morsel.update() functionality vulnerable.

    00000104
    56.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Heads up, #Fedora 43 admins! The new #Python 3.12.13 update (FEDORA-2026-ac5dd35f2d) is critical. It patches CVE-2026-0672, a header injection in http.cookies.Morsel that allows CRLF injection and response splitting. Read more: 👉 https://tinyurl.com/4z6nyn6f https://t.co/nDdCr9Jim9

    Post summary

    The Fedora 43 update is a critical patch for CVE‑2026‑0672, a header injection flaw in Python’s http.cookies.Morsel; no exploit code or active attacks are reported.

    0000045
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Heads up, #Fedora 43 admins! The new #Python 3.12.13 update (FEDORA-2026-ac5dd35f2d) is critical. It patches CVE-2026-0672, a header injection in http.cookies.Morsel that allows CRLF injection and response splitting. Read more: 👉 https://tinyurl.com/4z6nyn6f https://t.co/PnXpsmiRq1

    Post summary

    The tweet informs Fedora 43 administrators that the Python 3.12.13 update addresses CVE-2026-0672, a header injection flaw allowing CRLF injection and response splitting.

    0000041
    1.3K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2026-0672 impacts python in 7 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/443 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new medium‑severity CVE (CVE-2026‑0672) has been detected in AWS Lambda Python base images, with references to an issue discussion and additional details.

    0000032
    31 followersView on X
  • ThreatCluster@threatcluster
    Patch

    SUSE releases security updates for Python 3.6 and 3.10 on SLES and openSUSE, patching HTTP header injection flaws CVE-2025-11468, CVE-2026-0672, CVE-2026-0865 and CVE-2025-15366. Users should update. https://threatcluster.io/cluster/multiple-cves-addressed-in-python-http-header-injection-vuln-4575b4d8

    Post summary

    SUSE has released security updates for Python 3.6 and 3.10 to patch multiple HTTP header injection CVEs; users are advised to update.

    0000040
    79 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 Critical #Fedora 42 Python Update! 🚨 Patch CVE-2026-0672 & 4 other header injection flaws NOW. Update to Python 3.14.3 via DNF to secure your apps from HTTP response splitting & email attacks. Read more: 👉 https://tinyurl.com/559493pd #Security https://t.co/8iYhtRwJvQ

    Post summary

    Fedora 42’s Python 3.14.3 update contains a patch for CVE‑2026‑0672 and related header‑injection vulnerabilities, protecting against HTTP response splitting and email attacks.

    0000037
    1.3K followersView on X

Explore more