Skip to content

CVE-2026-3644 on CTRL-OS 26.05

Aliases: CVE-2026-3644

Packages: python313

Status: Plausible, Resolved

Advisory Information

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

Updates

2026-07-23 17:12 CEST

Metadata changes:

  • Status for package python313: “Resolved” (634df81a6bde9521cc2c14bc512ba5b2a89ae13f)

2026-07-23 17:12 CEST

Metadata changes:

  • Status for package python314: “Resolved” (e5a825f3cb5cde6a9a655154e641c580acb641fc)

2026-07-23 17:12 CEST

Metadata changes:

  • Status for package python315: “Resolved” (51c6e5d2b4f5f5c7e3eb08a28cc7d76f36506ade)

2026-07-23 17:12 CEST

Metadata changes:

  • Status for package python311: “Plausible
  • Status for package python312: “Plausible
  • Status for package python313: “Plausible
  • Status for package python314: “Plausible
  • Status for package python315: “Plausible

2026-06-01 17:44 CEST

Metadata changes:

  • Status for package python311: “New
  • Status for package python312: “New
  • Status for package python313: “New
  • Status for package python314: “New
  • Status for package python315: “New