Skip to content

3.10: CVE-2026-1502 fix for CR/LF in HTTP tunnel request headers appears unbackported #149197

@vulgraph

Description

@vulgraph

Hello 3.10 maintainers,

Was the security fix for CVE-2026-1502 (gh-146211, "Reject CR/LF in HTTP tunnel request headers") intentionally not yet ported to the 3.10 branch, or did it slip through?

Quick reference:

Since 3.10 is in security-fix-only mode and still receives security backports (latest commit on the branch is from 2026-04-13), this looks like an unbackported security fix rather than an EOL'd branch. Apologies if I've missed an in-flight cherry-pick — happy to close this if a backport PR is already queued.

Reporting in good faith from a port-credit / unbackported-CVE scan. No public PoC is being shared in this issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions