
CVE-2026-1502: CPython: HTTP client proxy tunnel headers not validated for CR/LF https://www.openwall.com/lists/oss-security/2026/04/11/4 CVE-2026-3446: CPython: Base64 decoding stops at first padded quad by default https://www.openwall.com/lists/oss-security/2026/04/11/5
Post summary
The post announces two new Python CVEs, linking to security mailing‑list discussions, without providing exploits, patches, or detailed technical data.



