Vulnerability Database

318,638

Total vulnerabilities in the database

CVE-2026-0672

When using http.cookies.Morsel, user-controlled cookie values and parameters can allow injecting HTTP headers into messages. Patch rejects all control characters within cookie names, values, and parameters.

  • Published: Jan 20, 2026
  • Updated: Jan 21, 2026
  • CVE: CVE-2026-0672
  • Exploit:

No technical information available.

CWEs: