CVE-2026-6019Disclosure(python / python)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch python python systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-150CWE-116

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • python

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-23); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
python

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-23: 2Mentions · 2026-06-27: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-04-23: 2Technical Details · 2026-06-27: 104-2306-27
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-232
Disclosure1General1
2026-06-271
Patch1
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ RLSA-2026:28581 acaba de sair para Rocky Linux 10! Corrige CVE-2026-4786 (injeção de comandos em http://webbrowser.open()) e CVE-2026-6019. Saiba mais:- &gt; http://tinyurl.com/3sfn6973 https://t.co/bBL9ozkMGO

    Post summary

    A new Rocky Linux 10 update (RLSA‑2026:28581) has been released, fixing CVE‑2026‑4786 (a command injection in webbrowser.open()) and CVE‑2026‑6019.

    1000076
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline &lt;script&gt; snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive se… https://www.cve.org/CVERecord?id=CVE-2026-6019

    Post summary

    The text reports a new CVE-2026-6019 describing an XSS flaw in http.cookies.Morsel.js_output(), providing some technical details but no PoC or exploitation evidence.

    00010118
    57.2K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-6019 http.cookies.Morsel.js_output() returns an inline

    Post summary

    The tweet references CVE-2026-6019 and hints at a problem involving http.cookies.Morsel.js_output() returning an inline value, but it offers no further technical detail, PoC, or evidence of exploitation.

    0000025
    72 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonpython---
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--
Apppythonpython3.15.0--

Explore more