CVE-2026-3644 on CTRL-OS 26.05
Aliases: CVE-2026-3644
Packages: python313
Status: Plausible, Resolved
Advisory Information
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().
Updates
2026-07-23 17:12 CEST
Metadata changes:
- Status for package
python313: “Resolved” (634df81a6bde9521cc2c14bc512ba5b2a89ae13f)
2026-07-23 17:12 CEST
Metadata changes:
- Status for package
python314: “Resolved” (e5a825f3cb5cde6a9a655154e641c580acb641fc)
2026-07-23 17:12 CEST
Metadata changes:
- Status for package
python315: “Resolved” (51c6e5d2b4f5f5c7e3eb08a28cc7d76f36506ade)
2026-07-23 17:12 CEST
Metadata changes:
- Status for package
python311: “Plausible” - Status for package
python312: “Plausible” - Status for package
python313: “Plausible” - Status for package
python314: “Plausible” - Status for package
python315: “Plausible”
2026-06-01 17:44 CEST
Metadata changes:
- Status for package
python311: “New” - Status for package
python312: “New” - Status for package
python313: “New” - Status for package
python314: “New” - Status for package
python315: “New”