The vendor explicitly identifies these products as affected by this CVE.
- firefox as a component of Red Hat Enterprise Linux 10
- firefox.src as a component of Red Hat Enterprise Linux 10
- python3.14 as a component of Red Hat Enterprise Linux 10
- python3.14-debug as a component of Red Hat Enterprise Linux 10
- python3.14-devel as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading-debug as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading-devel as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading-idle as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading-libs as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading-test as a component of Red Hat Enterprise Linux 10
- python3.14-freethreading-tkinter as a component of Red Hat Enterprise Linux 10
- Summary
- An injection flaw has been discovered in Python. When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
