CVE-2026-6019
Vulnerability Summary
Timeline
Description
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
CVSS Metrics
- v4.0•LOW•Score: 2.1CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- v4.0•LOW•Score: 2.1CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- v3.1•MEDIUM•Score: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- v3.1•MEDIUM•Score: 6.8CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Trends
Current EPSS score: 0.21%• Percentile: 12%
Techniques & Countermeasures
- CWE-150•Improper Neutralization of Escape, Meta, or Control Sequences
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.
- CWE-116•Improper Encoding or Escaping of Output
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
Affected Systems
- chainguard•python-3.10
all
- chainguard•python-3.11
all
- chainguard•python-3.12
all
- chainguard•python-3.13
< 3.13.13-r3
- chainguard•python-3.14
< 3.14.4-r4
- chainguard•python-3.9
all
- wolfi•python-3.10
all
- wolfi•python-3.11
all
- wolfi•python-3.12
all
- wolfi•python-3.13
< 3.13.13-r3
- wolfi•python-3.14
< 3.14.4-r4
- debian•pypy3
all | all | all | all
- debian•python3.11
all
- debian•python3.13
< 3.13.5-2+deb13u2 | < 3.13.14-1
- debian•python3.14
< 3.14.5~rc1-1
- debian•python3.9
all
- ubuntu•pypy3
all | all | all | all | all
- ubuntu•python2.7
all | < 2.7.6-8ubuntu0.6+esm30 | < 2.7.12-1ubuntu0~16.04.18+esm22 | < 2.7.17-1~18.04ubuntu1.13+esm15 | < 2.7.18-13ubuntu1.5+esm9
- ubuntu•python3.10
< 3.10.12-1~22.04.16
- ubuntu•python3.11
all | all | < 3.11.0~rc1-1~22.04.1+esm2
- ubuntu•python3.12
< 3.12.3-1ubuntu0.15
- ubuntu•python3.13
all
- ubuntu•python3.14
all | < 3.14.4-1ubuntu0.1
- ubuntu•python3.4
all | < 3.4.3-1ubuntu1~14.04.7+esm21
- ubuntu•python3.5
all | < 3.5.2-2ubuntu0~16.04.4~14.04.1+esm11 | < 3.5.2-2ubuntu0~16.04.13+esm25
- ubuntu•python3.6
all | < 3.6.9-1~18.04ubuntu1.13+esm10
- ubuntu•python3.7
all | < 3.7.5-2ubuntu1~18.04.2+esm11
- ubuntu•python3.8
all | < 3.8.0-3ubuntu1~18.04.2+esm11 | < 3.8.10-0ubuntu1~20.04.18+esm7
- ubuntu•python3.9
all | < 3.9.5-3ubuntu0~20.04.1+esm11
- python software foundation•cpython
< 3.15.0 | < 3.13.14 | ≥ 3.14.0a1, < 3.14.5rc1 | ≥ 3.15.0a1, < 3.15.0b1
- python•cpython
< 3.15.0
- python•python
< 3.15.0 | < 3.13.14 | ≥ 3.14.0, ≤ 3.14.4 | 3.15.0:alpha1 | 3.15.0:alpha2 | 3.15.0:alpha3 | 3.15.0:alpha4 | 3.15.0:alpha5 | 3.15.0:alpha6 | 3.15.0:alpha7 | 3.15.0:alpha8
- redhat•python-unversioned-command
< 0:3.14.5-2.hum1
- redhat•python3
< 0:3.14.5-2.hum1
- redhat•python3.11
< 0:3.11.15-4.3.hum1
- redhat•python3.12
< 0:3.12.13-3.2.hum1
- redhat•python3.13
< 0:3.13.14-1.1.hum1
- redhat•python3.14
< 0:3.14.5-2.hum1
References (26)
- https://github.com/python/cpython/pull/148848
- https://github.com/python/cpython/issues/90309
- https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/
- https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104
- https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c
- https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8
- https://access.redhat.com/errata/RHSA-2026:22952
- https://images.redhat.com/
- https://access.redhat.com/security/cve/CVE-2026-6019
- https://access.redhat.com/security/updates/classification/
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_22952.json
- https://bugzilla.redhat.com/show_bug.cgi?id=2460869
- https://www.cve.org/CVERecord?id=CVE-2026-6019
- https://nvd.nist.gov/vuln/detail/CVE-2026-6019
- https://access.redhat.com/errata/RHSA-2026:32980
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_32980.json
- https://access.redhat.com/errata/RHSA-2026:32997
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_32997.json
- https://access.redhat.com/errata/RHSA-2026:33885
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_33885.json
- https://ubuntu.com/security/CVE-2026-6019
- https://ubuntu.com/security/notices/USN-8509-1
- https://security-tracker.debian.org/tracker/CVE-2026-6019
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6019.json
- https://github.com/python/cpython
- https://ubuntu.com/security/notices/USN-8744-1