CVE-2026-3644General(python / python)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch python python systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-116

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • python

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-16); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
python

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-03-16: 2Mentions · 2026-03-17: 2Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-03-16: 2Technical Details · 2026-03-17: 203-1603-1704-1704-18
Signal classification3 categories
General
350.0%
Disclosure
233.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-162
Disclosure1General1
2026-03-172
Disclosure1General1
2026-04-171
General1
2026-04-181
Patch1
Full discourse6 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-4224: CPython: Stack overflow parsing XML with deeply nested DTD content models https://www.openwall.com/lists/oss-security/2026/03/16/4 CVE-2026-3644: CPython: Incomplete control character validation in http.cookies https://www.openwall.com/lists/oss-security/2026/03/16/5

    Post summary

    Two newly disclosed CPython vulnerabilities are listed with technical details, but no PoC, exploit, patch, or active exploitation is discussed.

    02095842
    4.4K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2026-3644 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/455 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS Lambda base images have been updated to remove CVE-2026-3644, with no evidence of current exploitation. The post signals that the CVE has been patched or otherwise eliminated in the latest scans.

    0000039
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2026-3644 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/455 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The tweet reports that CVE‑2026‑3644 is absent from recent AWS Lambda base image scans, linking to a related GitHub issue, without providing any exploit, patch, or technical details.

    0000019
    34 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3644 The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not pat… https://www.cve.org/CVERecord?id=CVE-2026-3644

    Post summary

    The passage highlights a technical issue with the incomplete fix of CVE-2026-0672 and references CVE-2026-3644, yet it offers no proof of exploitation, PoC, or patch information.

    00000104
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3644 - Incomplete control character validation in http.cookies Intel Report: https://ift.tt/NrDJGhI

    Post summary

    The alert announces CVE-2026-3644, noting incomplete control character validation in HTTP cookies, but provides no PoC, exploit, or patch details.

    0000048
    335 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3644 - Incomplete control character validation in http.cookies Intel Report: https://ift.tt/iZwMHso

    Post summary

    The alert references CVE‑2026‑3644 with a brief technical description but offers no evidence of active exploitation, PoC, or patch availability.

    0000041
    335 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonpython---
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--

Explore more