6.1

CVE-2026-6019

Exploit

BaseCookie.js_output() does not neutralize embedded characters

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Python ≫ Python Version < 3.13.14
Python ≫ Python Version >= 3.14.0 <= 3.14.4
Python ≫ Python Version 3.15.0 Update alpha1
Python ≫ Python Version 3.15.0 Update alpha2
Python ≫ Python Version 3.15.0 Update alpha3
Python ≫ Python Version 3.15.0 Update alpha4
Python ≫ Python Version 3.15.0 Update alpha5
Python ≫ Python Version 3.15.0 Update alpha6
Python ≫ Python Version 3.15.0 Update alpha7
Python ≫ Python Version 3.15.0 Update alpha8
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.135
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cna@python.org 2.1 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-116 Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

CWE-150 Improper Neutralization of Escape, Meta, or Control Sequences

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as escape, meta, or control character sequences when they are sent to a downstream component.

https://github.com/python/cpython/pull/148848
Patch
Issue Tracking
https://github.com/python/cpython/issues/90309
Exploit
Issue Tracking
https://github.com/python/cpython/commit/76b3923d688c0efc580658476c5f525ec8735104
Patch
https://github.com/python/cpython/commit/3c59b8b53fc75c7f9578d16fb8201ceb43e8f76c
Patch
https://github.com/python/cpython/commit/f795e042043dfe26c42e1971d4502c1cdc4c65b8
Patch
https://mail.python.org/archives/list/security-announce@python.org/thread/IVNWGV2BBNC3RHQAFS22UP4DY56SAXX3/
Vendor Advisory
Mailing List