CVE-2025-15282

User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.
CVSS

No CVSS.

Configurations

No configuration.

History

26 Jan 2026, 15:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/34d76b00dabde81a793bd06dd8ecb057838c4b38 -
  • () https://github.com/python/cpython/commit/3f396ca9d7bbe2a50ea6b8c9b27c0082884d9f80 -
  • () https://github.com/python/cpython/commit/4ed11d3cd288e6b90196a15c5a825a45d318fe47 -
  • () https://github.com/python/cpython/commit/a35ca3be5842505dab74dc0b90b89cde0405017a -

23 Jan 2026, 17:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/05356b1cc153108aaf27f3b72ce438af4aa218c0 -

20 Jan 2026, 23:16

Type Values Removed Values Added
References
  • () https://github.com/python/cpython/commit/f25509e78e8be6ea73c811ac2b8c928c28841b9f -

20 Jan 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-20 22:15

Updated : 2026-01-26 15:16


NVD link : CVE-2025-15282

Mitre link : CVE-2025-15282

CVE.ORG link : CVE-2025-15282


JSON object : View

Products Affected

No product.

CWE
CWE-93

Improper Neutralization of CRLF Sequences ('CRLF Injection')