There is a LOW severity vulnerability affecting CPython.

http.cookies.Morsel.js_output() returns an inline <script> snippet and only
escapes " for JavaScript string context. It does not neutralize the HTML
parser-sensitive sequence </script> inside the generated script element.
Mitigation base64-encodes the cookie value to disallow escaping using
cookie value.

Please see the linked CVE ID for the latest information on affected
versions:

* https://www.cve.org/CVERecord?id=CVE-2026-6019
* https://github.com/python/cpython/pull/148848
_______________________________________________
Security-announce mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/security-announce.python.org
Member address: [email protected]

Reply via email to