vulnerability
FreeBSD: VID-bfe9adc8-0224-11f1-8790-c5fb948922ad (CVE-2026-0865): python -- several security vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 6 | (AV:N/AC:M/Au:M/C:N/I:C/A:N) | Feb 4, 2026 | Feb 12, 2026 | Mar 25, 2026 |
Severity
6
CVSS
(AV:N/AC:M/Au:M/C:N/I:C/A:N)
Published
Feb 4, 2026
Added
Feb 12, 2026
Modified
Mar 25, 2026
Description
The Python project announces a new release with several security fixes: CVE-2026-1299: gh-144125: BytesGenerator will now refuse to serialize (write) headers that are unsafely folded or delimited; see verify_generated_headers. (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650). gh-143935: Fixed a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs. gh-143925: Reject control characters in data: URL media types. gh-143919: Reject control characters in http.cookies.Morsel fields and values. CVE-2026-0865: gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, values, and parameters.
Solutions
freebsd-upgrade-package-python310freebsd-upgrade-package-python311freebsd-upgrade-package-python312freebsd-upgrade-package-python313freebsd-upgrade-package-python313tfreebsd-upgrade-package-python314
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.