A vulnerability was found in Python CPython up to 3.14.x. It has been declared as critical. Affected by this issue is the function http.cookies.Morsel. Such manipulation leads to improper input validation.

This vulnerability is listed as CVE-2026-3644. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.