THREAT OPS › Threat News › [NVD] CVE-2026-3644 (HIGH 7.5) — The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the ou
[NVD] CVE-2026-3644 (HIGH 7.5) — The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the ou
CVE-2026-3644 CVSS: 7.5 HIGH Published: 2026-03-16T18:16:09.907
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().
Indicators of compromise
- CVE-2026-3644cve
- CVE-2026-0672cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-3644