CVE-2026-1502
Medium Severity
Description
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
Read more at https://www.tenable.com/cve/CVE-2026-1502
Related Vulnerabilities
- CVE-2026-3689: OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows remot MEDIUM
- CVE-2026-3446: When calling base64.b64decode() or related functions the decoding process would stop after encounter N/A
- CVE-2026-35647: OpenClaw before 2026.3.25 contains an access control vulnerability where verification notices bypass MEDIUM
- CVE-2026-35041: fast-jwt has a ReDoS when using RegExp in allowed* leading to CPU exhaustion during token verificati MEDIUM
- CVE-2026-34486: Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-2914 MEDIUM
Related Coverage
Threat Actors