Security Advisory

CVE-2026-0672

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-20 21:52:33
Last updated 2026-03-03 14:43:20
Assigner PSF
State PUBLISHED

Description

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.