https://seclists.org/oss-sec/2026/q1/320: [oss-security][CVE-2026-3644] CPython Incomplete control character validation in http.cookies
Published Mar 16, 2026
·Updated
Affected Software
1 affected component
pypi/cpython
Frequently Asked Questions
1
What is the severity of CVE-2026-3644?
CVE-2026-3644 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2026-3644?
To fix CVE-2026-3644, update to the latest version of CPython that addresses the incomplete control character validation.
3
What are the potential impacts of CVE-2026-3644?
The potential impacts of CVE-2026-3644 include improper handling of control characters in HTTP cookie parsing, which could lead to unexpected behavior.
4
Which versions of CPython are affected by CVE-2026-3644?
CVE-2026-3644 affects specific versions of CPython prior to the security patch release.
5
Is CVE-2026-3644 being actively exploited?
As of the publication date, there are no confirmed active exploits targeting CVE-2026-3644.