-------- Forwarded Message --------
Subject: [Security-announce][CVE-2026-1502] HTTP client proxy tunnel headers
not validated for CR/LF
Date: Fri, 10 Apr 2026 17:51:54 +0000
From: Seth Larson <[email protected]>
Reply-To: [email protected]
To: [email protected]
There is a MEDIUM severity vulnerability affecting CPython.
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
Please see the linked CVE ID for the latest information on affected versions:
* https://www.cve.org/CVERecord?id=CVE-2026-1502
* https://github.com/python/cpython/pull/146212