THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-3644 (HIGH 7.5) — The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the ou

[NVD] CVE-2026-3644 (HIGH 7.5) — The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the ou

lownvdPublished 2026-03-16

CVE-2026-3644 CVSS: 7.5 HIGH Published: 2026-03-16T18:16:09.907

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3644