CVE-2026-1502

Aliases:UBUNTU-CVE-2026-1502DEBIAN-CVE-2026-1502ALPINE-CVE-2026-1502CGA-67c6-67fc-p42gCGA-67mx-h3fh-x4cqCGA-7q5f-rxwg-6762CGA-944x-jfx5-h2p9CGA-f3fh-hj7q-j4cfCGA-fh47-vhf7-3mpvCGA-g74q-55r5-9jc3CGA-h9qm-m7fg-c98xCGA-j5x6-6r26-p78gCGA-7qqf-5wmc-5r5hCGA-ghg8-6h86-m46jCGA-r9fr-wc8w-5rr5
Awaiting Analysis
Published: 10 Apr 2026, 17:54
Last modified:13 Aug 2026, 00:28

Vulnerability Summary

Overall Risk (default)
low
23/100
CVSS Score
5.7 MEDIUM
v4.0 (cve.org)
EPSS Score
0.56% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Apr 2026, 17:54
Published
Vulnerability first disclosed
13 Aug 2026, 00:28
Last Modified
Vulnerability information updated

Description

CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.

CVSS Metrics

  • v4.0MEDIUMScore: 5.7CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  • v4.0MEDIUMScore: 5.7CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Trends

Current EPSS score: 0.56% Percentile: 46%

Techniques & Countermeasures

  • CWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')

    The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Affected Systems

  • alpinepython3

    < 3.12.14-r0 | < 3.12.14-r0 | < 3.12.14-r0

  • chainguardpython-3.10

    < 3.10.20-r4

  • chainguardpython-3.11

    < 3.11.15-r9

  • chainguardpython-3.12

    < 3.12.13-r3

  • chainguardpython-3.13

    < 3.13.13-r2

  • chainguardpython-3.14

    < 3.14.4-r3

  • chainguardpython-3.9

    all

  • wolfipython-3.10

    < 3.10.20-r4

  • wolfipython-3.11

    < 3.11.15-r9

  • wolfipython-3.12

    < 3.12.13-r3

  • wolfipython-3.13

    < 3.13.13-r2

  • wolfipython-3.14

    < 3.14.4-r3

  • debianpypy3

    all | all | all | < 7.3.22+dfsg-1

  • debianpython2.7

    all

  • debianpython3.11

    all

  • debianpython3.13

    < 3.13.5-2+deb13u3 | < 3.13.14-1

  • debianpython3.14

    < 3.14.5-1

  • debianpython3.9

    all

  • ubuntujython

    all | all | all | all | all | all | all

  • ubuntupypy3

    all | all | all | all | all

  • ubuntupython2.7

    all

  • ubuntupython3.10

    < 3.10.12-1~22.04.16

  • ubuntupython3.11

    all | all

  • ubuntupython3.12

    < 3.12.3-1ubuntu0.15

  • ubuntupython3.13

    all

  • ubuntupython3.14

    all | < 3.14.4-1ubuntu0.1

  • ubuntupython3.4

    all

  • ubuntupython3.5

    all

  • ubuntupython3.6

    all

  • ubuntupython3.7

    all

  • ubuntupython3.8

    all

  • ubuntupython3.9

    all

  • python software foundationcpython

    < 3.15.0 | ≥ 3.15.0a1, < 3.15.0 | < 3.14.5rc1 | < 3.13.14 | < 3.10.21 | ≥ 3.11.0, < 3.11.16 | ≥ 3.12.0, < 3.12.14 | ≥ 3.13.0, < 3.13.14 | ≥ 3.14.0a1, < 3.14.5rc1 | ≥ 3.15.0a1, < 3.15.0b1

References (18)