When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.
{ "cwe_ids": [] }
"https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-2026-5.json"