cve 2026 3644

  1. CVE-2026-3644: Python http.cookies Control Character Bug and Header Injection Risk

    The Microsoft Security Response Center page for CVE-2026-3644 currently appears to be unavailable, but the underlying issue is not mysterious: it points to incomplete control character validation in Python’s http.cookies module, a class of bug that can let attacker-controlled cookie data bleed...