Skip to content

[3.11] Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE 2026-3644, CVE-2026-4224#143

Open
stratakis wants to merge 6 commits intofedora-python:fedora-3.11from
stratakis:3.11-lets-roll
Open

[3.11] Security fixes for CVE-2026-1502, CVE-2026-4786, CVE-2026-6100, CVE-2026-2297, CVE 2026-3644, CVE-2026-4224#143
stratakis wants to merge 6 commits intofedora-python:fedora-3.11from
stratakis:3.11-lets-roll

Conversation

@stratakis
Copy link
Copy Markdown
Member

No description provided.

sethmlarson and others added 6 commits April 17, 2026 03:24
Reject CR/LF in HTTP tunnel request headers

Co-authored-by: Illia Volochii <illia.volochii@gmail.com>
Fix webbrowser `%action` substitution bypass of dash-prefix check
Fix a possible UAF in {LZMA,BZ2,_Zlib}Decompressor
Logging Bypass in Legacy .pyc File Handling
Incomplete control character validation in http.cookies

Co-authored-by: Victor Stinner <victor.stinner@gmail.com>
Stack overflow parsing XML with deeply nested DTD content models

Co-authored-by: Bénédikt Tran <10796600+picnixz@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants