CVE-2026-0865
ADVISORY - nistSummary
User-controlled header names and values containing newlines can allow injecting HTTP headers.
EPSS Score: 0.00132 (0.327)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
ADVISORY - redhat
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Docker
CREATED
UPDATED
ADVISORY ID
CVE-2026-0865
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
| Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
|---|---|---|---|---|---|
| python | dhi | - | - | >=3.13.0-alpha1,<3.13.13 | 3.13.13 |
| alpine/python-3.10 | apk | alpine | 3.23 | <3.10.20 | 3.10.20 |
| alpine/python-3.10 | apk | alpine | 3.23 | >=3.11.0-alpha1,<3.11.15 | 3.11.15 |
| alpine/python-3.10 | apk | alpine | 3.23 | >=3.12.0-alpha1,<3.12.13 | 3.12.13 |
| alpine/python-3.10 | apk | alpine | 3.23 | >=3.13.0-alpha1,<3.13.13 | 3.13.13 |
| alpine/python-3.10 | apk | alpine | 3.23 | >=3.14.0-alpha1,<3.14.4 | 3.14.4 |
| alpine/python-3.10 | apk | alpine | 3.23 | >=3.15.0-alpha1,<3.15.0-alpha7 | 3.15.0-alpha7 |
| alpine/python-3.11 | apk | alpine | 3.23 | <3.10.20 | 3.10.20 |
| alpine/python-3.11 | apk | alpine | 3.23 | >=3.11.0-alpha1,<3.11.15 | 3.11.15 |
| alpine/python-3.11 | apk | alpine | 3.23 | >=3.12.0-alpha1,<3.12.13 | 3.12.13 |
| alpine/python-3.11 | apk | alpine | 3.23 | >=3.13.0-alpha1,<3.13.13 | 3.13.13 |
| alpine/python-3.11 | apk | alpine | 3.23 | >=3.14.0-alpha1,<3.14.4 | 3.14.4 |
| alpine/python-3.11 | apk | alpine | 3.23 | >=3.15.0-alpha1,<3.15.0-alpha7 | 3.15.0-alpha7 |
| alpine/python-3.12 | apk | alpine | 3.23 | <3.10.20 | 3.10.20 |
| alpine/python-3.12 | apk | alpine | 3.23 | >=3.11.0-alpha1,<3.11.15 | 3.11.15 |
| alpine/python-3.12 | apk | alpine | 3.23 | >=3.12.0-alpha1,<3.12.13 | 3.12.13 |
| alpine/python-3.12 | apk | alpine | 3.23 | >=3.13.0-alpha1,<3.13.13 | 3.13.13 |
| alpine/python-3.12 | apk | alpine | 3.23 | >=3.14.0-alpha1,<3.14.4 | 3.14.4 |
| alpine/python-3.12 | apk | alpine | 3.23 | >=3.15.0-alpha1,<3.15.0-alpha7 | 3.15.0-alpha7 |
| alpine/python-3.13 | apk | alpine | 3.23 | <3.10.20 | 3.10.20 |
| alpine/python-3.13 | apk | alpine | 3.23 | >=3.11.0-alpha1,<3.11.15 | 3.11.15 |
| alpine/python-3.13 | apk | alpine | 3.23 | >=3.12.0-alpha1,<3.12.13 | 3.12.13 |
| alpine/python-3.13 | apk | alpine | 3.23 | >=3.13.0-alpha1,<3.13.13 | 3.13.13 |
| alpine/python-3.13 | apk | alpine | 3.23 | >=3.14.0-alpha1,<3.14.4 | 3.14.4 |
| alpine/python-3.13 | apk | alpine | 3.23 | >=3.15.0-alpha1,<3.15.0-alpha7 | 3.15.0-alpha7 |
| alpine/python-3.14 | apk | alpine | 3.23 | <3.10.20 | 3.10.20 |
| alpine/python-3.14 | apk | alpine | 3.23 | >=3.11.0-alpha1,<3.11.15 | 3.11.15 |
| alpine/python-3.14 | apk | alpine | 3.23 | >=3.12.0-alpha1,<3.12.13 | 3.12.13 |
| alpine/python-3.14 | apk | alpine | 3.23 | >=3.13.0-alpha1,<3.13.13 | 3.13.13 |
| alpine/python-3.14 | apk | alpine | 3.23 | >=3.14.0-alpha1,<3.14.4 | 3.14.4 |
| alpine/python-3.14 | apk | alpine | 3.23 | >=3.15.0-alpha1,<3.15.0-alpha7 | 3.15.0-alpha7 |
| python | dhi | - | - | <3.10.20 | 3.10.20 |
| python | dhi | - | - | >=3.11.0-alpha1,<3.11.15 | 3.11.15 |
| python | dhi | - | - | >=3.12.0-alpha1,<3.12.13 | 3.12.13 |
| python | dhi | - | - | >=3.14.0-alpha1,<3.14.4 | 3.14.4 |
| python | dhi | - | - | >=3.15.0-alpha1,<3.15.0-alpha7 | 3.15.0-alpha7 |
Severity and metrics
No CVSS data available from this advisory.
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-0865
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
5.9mediumDebian
CREATED
UPDATED
ADVISORY IDCVE-2026-0865
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Ubuntu
CREATED
UPDATED
ADVISORY IDCVE-2026-0865
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumAlma
CREATED
UPDATED
ADVISORY IDALSA-2026:2128
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumAlma
CREATED
UPDATED
ADVISORY IDALSA-2026:4168
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumAlma
CREATED
UPDATED
ADVISORY IDALSA-2026:4463
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumAlma
CREATED
UPDATED
ADVISORY IDALSA-2026:4473
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumAmazon
CREATED
UPDATED
ADVISORY IDALAS2-2026-3184
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumAmazon
CREATED
UPDATED
ADVISORY IDALAS2-2026-3185
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumAmazon
CREATED
UPDATED
ADVISORY IDALAS2023-2026-1437
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumAmazon
CREATED
UPDATED
ADVISORY IDALAS2023-2026-1444
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumAmazon
CREATED
UPDATED
ADVISORY IDALAS2023-2026-1447
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumBitnami
CREATED
UPDATED
ADVISORY ID
BIT-libpython-2026-0865
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
5.9mediumBitnami
CREATED
UPDATED
ADVISORY ID
BIT-python-2026-0865
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
5.9mediumBitnami
CREATED
UPDATED
ADVISORY ID
BIT-python-min-2026-0865
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
5.9mediumRed Hat
CREATED
UPDATED
ADVISORY IDCVE-2026-0865
EXPLOITABILITY SCORE
0.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
4.5mediumRocky
CREATED
UPDATED
ADVISORY IDRLSA-2026:4168
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AlowRocky
CREATED
UPDATED
ADVISORY IDRLSA-2026:4463
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AlowRocky
CREATED
UPDATED
ADVISORY IDRLSA-2026:4473
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AlowRocky
CREATED
UPDATED
ADVISORY IDRLSA-2026:4713
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AlowOracle
CREATED
UPDATED
ADVISORY IDELSA-2026-2128
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumOracle
CREATED
UPDATED
ADVISORY IDELSA-2026-4463
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumOracle
CREATED
UPDATED
ADVISORY IDELSA-2026-4473
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumOracle
CREATED
UPDATED
ADVISORY IDELSA-2026-4713
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumChainguard
CREATED
UPDATED
ADVISORY ID
CGA-q8pr-wxrw-3vx3
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
minimos
CREATED
UPDATED
ADVISORY ID
MINI-8fcx-736x-vj46
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
minimos
CREATED
UPDATED
ADVISORY ID
MINI-99vm-pp5c-jc8p
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
minimos
CREATED
UPDATED
ADVISORY ID
MINI-fh4c-v6j3-p5x7
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
minimos
CREATED
UPDATED
ADVISORY ID
MINI-fp4p-227x-m3w2
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
minimos
CREATED
UPDATED
ADVISORY ID
MINI-jqfv-cqgf-j82c
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-