CVE-2026-1502Patch

LOWCVSS 5.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-93

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 2 mentions (2026-04-11); latest day: 1
  • 9 total mentions across 8 days

Deep dive

Activity timeline9 mentions / 8d
01122Mentions · 2026-04-10: 1Mentions · 2026-04-11: 2Mentions · 2026-04-20: 1Mentions · 2026-04-25: 1Mentions · 2026-04-28: 1Mentions · 2026-05-18: 1Mentions · 2026-05-23: 1Mentions · 2026-05-24: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-25: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-24: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-11: 2Technical Details · 2026-04-20: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-28: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-24: 104-1004-1104-2004-2504-2805-1805-2305-24
Signal classification3 categories
Patch
444.4%
Disclosure
333.3%
General
222.2%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-101
General1
2026-04-112
Disclosure1General1
2026-04-201
Disclosure1
2026-04-251
Disclosure1
2026-04-281
Patch1
2026-05-181
Patch1
2026-05-231
Patch1
2026-05-241
Patch1
Full discourse9 posts
  • Open Source Security mailing list@oss_security
    General

    CVE-2026-1502: CPython: HTTP client proxy tunnel headers not validated for CR/LF https://www.openwall.com/lists/oss-security/2026/04/11/4 CVE-2026-3446: CPython: Base64 decoding stops at first padded quad by default https://www.openwall.com/lists/oss-security/2026/04/11/5

    Post summary

    The text lists two recent CVEs with brief titles and links to Openwall security mailing list posts, providing minimal technical description but no PoC, exploit code, patch info, or active exploitation reports.

    00080613
    4.6K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    CVE-2026-1502 (HTTP injection) and CVE-2026-4786 (command injection) hit Python 3.14 on Fedora. Don't just patch today. Build automation that finds ANY CVE. Read -> https://tinyurl.com/2krzcetb #Fedora #Security https://t.co/MAxXE6g3II

    Post summary

    Two new CVEs impacting Python 3.14 on Fedora are disclosed, with a call to patch and automate CVE detection.

    1000045
    1.5K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-1502 CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. https://www.cve.org/CVERecord?id=CVE-2026-1502

    Post summary

    The post references CVE-2026-1502 and briefly describes a technical issue involving CR/LF bytes in proxy tunnel headers, without offering PoC, exploit, or patch details.

    00010108
    57.0K followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora 42 and 43 ship fixes for Python 3.15 bugs CVE-2026-1502, -6100, -4786, -5713, -3219 enabling arbitrary code execution via http://webbrowser.open command injection and use-after-free. https://threatcluster.io/cluster/multiple-cves-in-python-315-affect-fedora-users-467e6a4a

    Post summary

    Fedora 42 and 43 have released patches for several Python 3.15 CVEs that enabled arbitrary code execution via webbrowser.open command injection and use-after-free; no active exploitation or PoC was reported in the text.

    00000107
    279 followersView on X
  • Rob Savoury@RobSavoury
    Patch

    Latest Python 3.14.5 release (including fixes for CVE-2026-1502, CVE-2026-4786, and CVE-2026-5713) is now available to #SavOS PPA users of #Ubuntu #Linux at ppa:savoury1/python-3.14 (https://launchpad.net/~savoury1/+archive/ubuntu/python-3.14) for all PPA supported LTS releases.

    Post summary

    The post announces that the latest Python 3.14.5 release, available through the SavOS PPA, includes fixes for three CVEs and provides a patch for Ubuntu users.

    0000075
    46 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: SUSE releases critical Python3 and Python310 patches for CVE-2026-1502, CVE-2026-4786 and 3 more flaws enabling command injection and code execution on openSUSE systems. https://threatcluster.io/cluster/critical-python-vulnerabilities-in-opensuse-affecting-comman-9dc1aaa1

    Post summary

    The text announces SUSE’s release of critical patches for Python3 and Python310 vulnerabilities that could allow command injection and code execution on openSUSE systems.

    0000064
    275 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora updates MinGW Windows python3 to patch CVE-2026-4786, CVE-2026-6100, CVE-2026-3479, CVE-2026-1502 enabling code execution, data leaks, and HTTP header injection. https://threatcluster.io/cluster/multiple-cves-addressed-in-fedora-python3-updates-f6a2a99b

    Post summary

    Fedora released python3 updates that patch multiple CVEs, addressing code execution, data leak, and HTTP header injection vulnerabilities.

    0000063
    166 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical Python flaws CVE-2026-1502 and CVE-2026-6100 hit 3.10, 3.12, 3.15 on Ubuntu 22.04 and Fedora 42-43, enabling HTTP header injection and code execution, patches now live. https://threatcluster.io/cluster/critical-python-vulnerabilities-affect-multiple-versions-3291ef10

    Post summary

    Critical Python CVE-2026-1502 and CVE-2026-6100 are disclosed, affecting Ubuntu 22.04 and Fedora 42‑43, enabling HTTP header injection and code execution, and patches are now available.

    0000079
    160 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CPython [CVE-2026-1502] HTTP client proxy tunnel headers not validated for CR/LF Intel Report: https://ift.tt/TJKOyhi

    Post summary

    An alert about a newly disclosed CPython vulnerability (CVE-2026-1502) involving improper validation of HTTP proxy tunnel headers for CR/LF characters. The post references the issue but does not provide PoC, exploit, or mitigation details.

    0000025
    280 followersView on X

Explore more