UBUNTU-CVE-2026-3644
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-3644
UBUNTU-CVE-2026-3644
Summary:
Details: The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().
References: https://ubuntu.com/security/CVE-2026-3644, https://www.cve.org/CVERecord?id=CVE-2026-3644, https://mail.python.org/archives/list/[email protected]/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/, https://github.com/python/cpython/pull/145600, https://ubuntu.com/security/notices/USN-8509-1, https://ubuntu.com/security/notices/USN-8744-1
Affected packages
Package
Name: python2.7
Purl: pkg:deb/ubuntu/python2.7?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
