CVE-2026-3644 @ Matrix
Status
accepted_risk
Priority
2.25
Match score
4.0
Risk
Other
Remote
priv:user
CVSS
7.5 HIGH
Reason
cpe: python; pkgs: python, python-apt-common; version: in-range: python-2.7.16-1, python-apt-common-2.6.0; debian:bookworm python3.11 open
Created
2026-08-05T14:05:15Z
Updated
2026-08-22T10:15:58Z
Closed
2026-08-05T14:42:09Z
Package interrogation (copy)
Run on the host — click to copy a command. Debian/apt
| Package | Commands |
|---|---|
| python-2.7.16-1 | |
| python-apt-common-2.6.0 |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: python · python-apt-common
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2026-68770 | 9.8 | morris, mufasa | does_not_affect | python | — | ||
| CVE-2026-4224 | 7.5 | Archive, Library, Saiph, morris, mufasa | accepted_risk, does_not_affect | python | — | ||
| CVE-2026-7210 | 7.5 | Archive, Library, Matrix, Saiph, morris … | accepted_risk, not_applicable | python | → CVE-2026-15308 | ||
| CVE-2026-15308 | 7.5 | Archive, Library, Matrix, Saiph, morris … | accepted_risk | python | — | ||
| CVE-2026-59939 | 7.5 | Bullseye, Matrix, Silk | new | python | — | ||
| CVE-2026-30922 | 7.5 | Library | not_applicable | python | → CVE-2026-59884 | ||
| CVE-2026-59886 | 7.5 | Library | not_applicable | python | → CVE-2026-59884 | ||
| CVE-2026-7246 | 7.2 | Silk | does_not_affect | python | — |
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Host OS / kernel
OS
Debian GNU/Linux 12 (bookworm)
(12)
· debian
Arch
x86_64
kernel_release
uname -r → 6.1.0-52-amd64kernel_version
uname -v → #1 SMP PREEMPT_DYNAMIC Debian 6.1.180-1 (2026-08-03)For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| morris | does_not_affect | 7.5 | 2026-08-22T10:15:58Z | Open |
| mufasa | does_not_affect | 7.5 | 2026-08-22T10:15:58Z | Open |
| Library | accepted_risk | 2.25 | 2026-08-22T10:15:58Z | Open |
| Archive | accepted_risk | 1.12 | 2026-08-22T10:15:58Z | Open |
| Saiph | accepted_risk | 1.12 | 2026-08-22T10:15:58Z | Open |
Description
The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().
Determination
Vulnerable python-2.7.13-2 python-stdlib-2.7.13-2 python-minimal-2.7.13-2 -> 2.7.13-2 is Vulnerable No public Access t is a header injection issue that can lead to response splitting, cache poisoning, or session fixation in certain application designs. Most likely no application code exposure
Update status
Add note only
Mitigation log
2026-08-05T14:38:30Z — affects
Vulnerable
python-2.7.13-2
python-stdlib-2.7.13-2
python-minimal-2.7.13-2 -> 2.7.13-2 is Vulnerable
2026-08-05T14:42:09Z — accepted_risk
No public Access
t is a header injection issue that can lead to response splitting, cache poisoning, or session fixation in certain application designs.
Most likely no application code exposure
References
- https://github.com/python/cpython/commit/3974092b037f9a3b000fb15b48ea61ce3b25d330
- https://github.com/python/cpython/commit/556aa098e738b127c714866f819b4abe2f7593d8
- https://github.com/python/cpython/commit/57e88c1cf95e1481b94ae57abe1010469d47a6b4
- https://github.com/python/cpython/commit/62ceb396fcbe69da1ded3702de586f4072b590dd
- https://github.com/python/cpython/commit/d16ecc6c3626f0e2cc8f08c309c83934e8a979dd
- https://github.com/python/cpython/commit/dae4b1a21f8df4570e30986affd61bbe4ade4cef
- https://github.com/python/cpython/issues/145599
- https://github.com/python/cpython/pull/145600
- https://mail.python.org/archives/list/security-announce@python.org/thread/H6CADMBCDRFGWCMOXWUIHFJNV43GABJ7/
NVD: CVE-2026-3644