NONE · 0

CVE-2026-0672

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and param...

Vulnerability Description

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-0672?

CVE-2026-0672 is a documented vulnerability. When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and param...

How severe is CVE-2026-0672?

CVSS scoring is not yet available for CVE-2026-0672. Check NVD for updates.

Is there a patch for CVE-2026-0672?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.