CVE-2026-0865Patch

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

User-controlled header names and values containing newlines can allow injecting HTTP headers.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-25); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-25: 1Mentions · 2026-02-28: 1Mentions · 2026-03-07: 1Mentions · 2026-03-19: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-28: 102-2502-2803-0703-19
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-251
Patch1
2026-02-281
Patch1
2026-03-071
Disclosure1
2026-03-191
Patch1
Full discourse4 posts
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-0865 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/444 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS has removed CVE-2026-0865 from its latest Lambda base images, indicating the vulnerability has been patched with no evidence of current exploitation.

    0000043
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2026-0865 impacts python in 7 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/444 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new medium‑severity vulnerability (CVE‑2026‑0865) affecting Python in seven AWS Lambda base images has been reported, with issue details posted on GitHub and further information available on Lambdawatchdog.

    0000039
    31 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fedora 42 and 43 ship security updates for python3.9, fixing critical command injection flaws (CVE-2026-1299, CVE-2026-0865, CVE-2025-15366, CVE-2025-15367). Developers should update. #Linux https://threatcluster.io/cluster/fedora-python-39-command-injection-vulnerabilities-addressed-ae49cdaf

    Post summary

    Fedora 42 and 43 release security updates for Python 3.9 that address multiple critical command injection vulnerabilities; developers are urged to apply these patches.

    00000146
    83 followersView on X
  • ThreatCluster@threatcluster
    Patch

    SUSE releases security updates for Python 3.6 and 3.10 on SLES and openSUSE, patching HTTP header injection flaws CVE-2025-11468, CVE-2026-0672, CVE-2026-0865 and CVE-2025-15366. Users should update. https://threatcluster.io/cluster/multiple-cves-addressed-in-python-http-header-injection-vuln-4575b4d8

    Post summary

    SUSE has issued security updates for Python 3.6 and 3.10 on SLES and openSUSE, addressing multiple HTTP header injection CVEs; users are advised to apply the patches.

    0000040
    79 followersView on X

Explore more