CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF
Published Apr 10, 2026
·Updated
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
Other sources
HTTP client proxy tunnel headers not validated for CR/LF
— Microsoft
Affected Software
3 affected componentsFixes available
Python Software Foundation CPython
Microsoft azl3 python3 3.12.9-10
Microsoft azl3 python3 3.12.9-11
Event History
Apr 10, 2026
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·07:01 PM
DescriptionSeverityAffected Software
Apr 15, 2026
Data Sourced
via Microsoft·08:04 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:04 AM
Affected Software
Updated
via Microsoft·08:04 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-1502?
The severity of CVE-2026-1502 is rated as medium with a CVSS score of 5.7.
2
How do I fix CVE-2026-1502?
To fix CVE-2026-1502, ensure that the HTTP client proxy tunnel headers validate CR/LF sequences properly.
3
What vulnerability type is CVE-2026-1502 classified as?
CVE-2026-1502 is classified as a CRLF Injection vulnerability.
4
Which software is affected by CVE-2026-1502?
CVE-2026-1502 affects various versions of CPython from the Python Software Foundation and Microsoft azl3 Python 3.
5
What are the risks associated with CVE-2026-1502?
The risks associated with CVE-2026-1502 include potential HTTP response splitting and malicious data manipulation through improper validation.