The vendor explicitly identifies these products as affected by this CVE.
- firefox as a component of Red Hat Enterprise Linux 10
- firefox.src as a component of Red Hat Enterprise Linux 10
- python3.14 as a component of Red Hat Enterprise Linux 10
- python3.14-debug as a component of Red Hat Enterprise Linux 10
- python3.14-devel as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading-debug as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading-devel as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading-idle as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading-libs as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading-test as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading-tkinter as a component of Red Hat Enterprise Linux 10
- Summary
- Missing newline filtering has been discovered in Python. User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
