CVE-2026-1502
Medium Severity
Description
CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.
Read more at https://www.tenable.com/cve/CVE-2026-1502
Related Vulnerabilities
- CVE-2026-31940: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.p HIGH
- CVE-2026-34477: The fix for CVE-2025-68161 https://logging.apache.org/security.html#CVE-2025-68161 was incomplete: i MEDIUM
- CVE-2026-40154: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched templat CRITICAL
- CVE-2026-28704: Emocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same HIGH
- CVE-2026-4158: KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerab HIGH
Related Coverage
Threat Actors