Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 9 min 104 bronnen 3 kritiek 12 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2026-6019

MEDIUM · 6.1 CVSS Gepubliceerd: CWE-150

Beschrijving

http.cookies.Morsel.js_output() returns an inline snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

Vendors

Python

Affected products

Python

References