Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-44431

Опубликовано: 13 мая 2026
Источник: debian
EPSS Низкий

Описание

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-urllib3fixed2.7.0-1package

Примечания

  • https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc

  • Fixed by: https://github.com/urllib3/urllib3/commit/5ec0de499b9166ca71c65ab04f2a7e4eb0d66fcc (2.7.0)

EPSS

Процентиль: 26%
0.00331
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

CVSS3: 5.9
redhat
3 месяца назад

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

CVSS3: 5.3
nvd
3 месяца назад

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

msrc
3 месяца назад

urllib3: Sensitive headers forwarded across origins in proxied low-level redirects

suse-cvrf
около 2 месяцев назад

Security update for python-urllib3_1

EPSS

Процентиль: 26%
0.00331
Низкий