CVE detail
CVE-2026-3644
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
Information published.
vendormsrc.microsoft.comJun 3, 2026, 8:46 AM- https://mail.python.org/archives/list/[email protected]/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/mail.python.org
No excerpt available.
Vendor Advisorymail.python.orgMar 16, 2026, 6:16 PM No excerpt available.
Exploitgithub.comMar 16, 2026, 6:16 PMNo excerpt available.
Exploitgithub.comMar 16, 2026, 6:16 PMNo excerpt available.
Exploitgithub.comMar 16, 2026, 6:16 PMNo excerpt available.
Exploitgithub.comMar 16, 2026, 6:16 PMNo excerpt available.
Exploitgithub.comMar 16, 2026, 6:16 PMNo excerpt available.
Exploitgithub.comMar 16, 2026, 6:16 PMNo excerpt available.
Exploitgithub.comMar 16, 2026, 6:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-54133CVSS 9.8 · Critical
jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versio…
- CVE-2026-28907CVSS 8.1 · High
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vi…
- CVE-2026-42810CVSS 9.4 · Critical
Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters app…
- CVE-2026-40871CVSS 7.2 · High
mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerability in the quarantine_category…
- CVE-2026-33436CVSS 3.1 · Low
Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to 2.0.0, file upload endpoints render user-supplied filenames…
- CVE-2026-33758CVSS 9.4 · Critical
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role wi…