PT-2026-32007 · Linux Mint+3 · Linuxmint+3

·

CVE-2026-1502

·

Published

2026-03-20

·

Updated

2026-08-28

CVSS v4.0

9.1

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions The product name cannot be determined. (affected versions not specified)
Description The system does not reject carriage return and line feed (CR/LF) bytes in HTTP client proxy tunnel headers or the host.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:10950
ALSA-2026:19019
ALSA-2026:19064
ALSA-2026:19176
ALSA-2026:19177
AZL-82899
BDU:2026-09515
BIT-LIBPYTHON-2026-1502
BIT-PYTHON-2026-1502
BIT-PYTHON-MIN-2026-1502
CVE-2026-1502
ECHO-6948-71F0-8930
OESA-2026-2115
OESA-2026-2116
OESA-2026-2117
OPENSUSE-SU-2026:10647-1
OPENSUSE-SU-2026:10648-1
OPENSUSE-SU-2026:10667-1
OPENSUSE-SU-2026:11068-1
OPENSUSE-SU-2026:11100-1
OPENSUSE-SU-2026:11181-1
OPENSUSE-SU-2026:21459-1
PSF-2026-15
RHSA-2026:10117
RHSA-2026:10950
RHSA-2026:19019
RHSA-2026:19064
RHSA-2026:19176
RHSA-2026:19177
RHSA-2026:8822
RHSA-2026:8824
RHSA-2026:9228
SUSE-SU-2026:1715-1
SUSE-SU-2026:1818-1
SUSE-SU-2026:1937-1
SUSE-SU-2026:1947-1
SUSE-SU-2026:2055-1
SUSE-SU-2026:22959-1
SUSE-SU-2026:23191-1
SUSE-SU-2026:23212-1
SUSE-SU-2026:2464-1
SUSE-SU-2026:3104-1
SUSE-SU-2026:3132-1
SUSE-SU-2026:3855-1
USN-8509-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu