User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.
https://mail.python.org/archives/list/[email protected]/thread/X66HL7SISGJT33J53OHXMZT4DFLMHVKF/
https://github.com/python/cpython/pull/143926
https://github.com/python/cpython/issues/143925
https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f
https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a
https://github.com/python/cpython/commit/4ed11d3cd288e6b90196a15c5a825a45d318fe47
https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80
https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38
https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0
Published: 2026-01-20
Updated: 2026-01-26
Base Score: 6.4
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N
Severity: Medium
Base Score: 6.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity: Medium
Base Score: 6
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N
Severity: Medium
EPSS: 0.00047