CVE-2026-6019

Aliases:RHSA-2026:22952RHSA-2026:32980RHSA-2026:32997RHSA-2026:33885UBUNTU-CVE-2026-6019DEBIAN-CVE-2026-6019CGA-2rxc-qq2g-w4hfCGA-477g-5pph-75mjCGA-4q3r-438p-rwv3CGA-5qxj-c966-pvpwCGA-6rw5-pv82-g8jwCGA-g7j7-w4vj-6cfxCGA-hjp9-xq8m-3jr3CGA-m623-m4mg-xfgpCGA-5gw4-663p-cc7qCGA-cmfw-mf93-h33mCGA-qpp8-2qh9-qw2xCGA-qxmw-675j-q4q2
Analyzed
Published: 22 Apr 2026, 19:28
Last modified:10 Jun 2026, 18:58

Vulnerability Summary

Overall Risk (default)
medium
34/100
CVSS Score
6.1 MEDIUM
v3.1 (nvd)
EPSS Score
0.21% LOW
0% probability -0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

22 Apr 2026, 19:28
Published
Vulnerability first disclosed
10 Jun 2026, 18:58
Last Modified
Vulnerability information updated

Description

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

CVSS Metrics

  • v4.0LOWScore: 2.1CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  • v4.0LOWScore: 2.1CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • v3.1MEDIUMScore: 6.8CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.21% Percentile: 12%

Techniques & Countermeasures

  • CWE-150Improper Neutralization of Escape, Meta, or Control Sequences

    The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.

  • CWE-116Improper Encoding or Escaping of Output

    The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Affected Systems

  • chainguardpython-3.10

    all

  • chainguardpython-3.11

    all

  • chainguardpython-3.12

    all

  • chainguardpython-3.13

    < 3.13.13-r3

  • chainguardpython-3.14

    < 3.14.4-r4

  • chainguardpython-3.9

    all

  • wolfipython-3.10

    all

  • wolfipython-3.11

    all

  • wolfipython-3.12

    all

  • wolfipython-3.13

    < 3.13.13-r3

  • wolfipython-3.14

    < 3.14.4-r4

  • debianpypy3

    all | all | all | all

  • debianpython3.11

    all

  • debianpython3.13

    < 3.13.5-2+deb13u2 | < 3.13.14-1

  • debianpython3.14

    < 3.14.5~rc1-1

  • debianpython3.9

    all

  • ubuntupypy3

    all | all | all | all | all

  • ubuntupython2.7

    all | < 2.7.6-8ubuntu0.6+esm30 | < 2.7.12-1ubuntu0~16.04.18+esm22 | < 2.7.17-1~18.04ubuntu1.13+esm15 | < 2.7.18-13ubuntu1.5+esm9

  • ubuntupython3.10

    < 3.10.12-1~22.04.16

  • ubuntupython3.11

    all | all | < 3.11.0~rc1-1~22.04.1+esm2

  • ubuntupython3.12

    < 3.12.3-1ubuntu0.15

  • ubuntupython3.13

    all

  • ubuntupython3.14

    all | < 3.14.4-1ubuntu0.1

  • ubuntupython3.4

    all | < 3.4.3-1ubuntu1~14.04.7+esm21

  • ubuntupython3.5

    all | < 3.5.2-2ubuntu0~16.04.4~14.04.1+esm11 | < 3.5.2-2ubuntu0~16.04.13+esm25

  • ubuntupython3.6

    all | < 3.6.9-1~18.04ubuntu1.13+esm10

  • ubuntupython3.7

    all | < 3.7.5-2ubuntu1~18.04.2+esm11

  • ubuntupython3.8

    all | < 3.8.0-3ubuntu1~18.04.2+esm11 | < 3.8.10-0ubuntu1~20.04.18+esm7

  • ubuntupython3.9

    all | < 3.9.5-3ubuntu0~20.04.1+esm11

  • python software foundationcpython

    < 3.15.0 | < 3.13.14 | ≥ 3.14.0a1, < 3.14.5rc1 | ≥ 3.15.0a1, < 3.15.0b1

  • pythoncpython

    < 3.15.0

  • pythonpython

    < 3.15.0 | < 3.13.14 | ≥ 3.14.0, ≤ 3.14.4 | 3.15.0:alpha1 | 3.15.0:alpha2 | 3.15.0:alpha3 | 3.15.0:alpha4 | 3.15.0:alpha5 | 3.15.0:alpha6 | 3.15.0:alpha7 | 3.15.0:alpha8

  • redhatpython-unversioned-command

    < 0:3.14.5-2.hum1

  • redhatpython3

    < 0:3.14.5-2.hum1

  • redhatpython3.11

    < 0:3.11.15-4.3.hum1

  • redhatpython3.12

    < 0:3.12.13-3.2.hum1

  • redhatpython3.13

    < 0:3.13.14-1.1.hum1

  • redhatpython3.14

    < 0:3.14.5-2.hum1

References (26)