Skip to content

3.10: CVE-2026-1502 fix for CR/LF in HTTP tunnel request headers appears unbackported #149197

Description

@vulgraph

Hello 3.10 maintainers,

Was the security fix for CVE-2026-1502 (gh-146211, "Reject CR/LF in HTTP tunnel request headers") intentionally not yet ported to the 3.10 branch, or did it slip through?

Quick reference:

Since 3.10 is in security-fix-only mode and still receives security backports (latest commit on the branch is from 2026-04-13), this looks like an unbackported security fix rather than an EOL'd branch. Apologies if I've missed an in-flight cherry-pick — happy to close this if a backport PR is already queued.

Reporting in good faith from a port-credit / unbackported-CVE scan. No public PoC is being shared in this issue.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions