CVE-2026-1502
Medium Severity
Description
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
Read more at https://www.tenable.com/cve/CVE-2026-1502
Related Vulnerabilities
- CVE-2026-40069: bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts MEDIUM
- CVE-2026-40198: Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP MEDIUM
- CVE-2026-40177: ajenti.plugin.core has password bypass when 2FA is activated CRITICAL
- CVE-2026-35659: OpenClaw before 2026.3.22 contains a service discovery vulnerability where TXT metadata from Bonjour MEDIUM
- CVE-2026-6027: A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the func CRITICAL
Related Coverage
Threat Actors