Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44431

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

A flaw was found in urllib3, an HTTP client library for Python. When using the low-level API via ProxyManager.connection_from_url().urlopen() with assert_same_host=False, cross-origin redirects can still forward sensitive headers. This could allow a remote attacker to gain unauthorized access to sensitive information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Out of support scope
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/bitwarden-sdk-server-rhel9Not affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-bundleNot affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-rhel9Not affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-rhel9-operatorAffected
Migration Toolkit for Containersrhmtc/openshift-migration-rhel8-operatorAffected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-rhel9-operatorFix deferred
Migration Toolkit for Virtualizationmtv-candidate/mtv-rhel9-operatorWill not fix
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2477167urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers

EPSS

Процентиль: 26%
0.00331
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

CVSS3: 5.3
nvd
3 месяца назад

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

msrc
3 месяца назад

urllib3: Sensitive headers forwarded across origins in proxied low-level redirects

CVSS3: 5.3
debian
3 месяца назад

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7. ...

suse-cvrf
около 2 месяцев назад

Security update for python-urllib3_1

EPSS

Процентиль: 26%
0.00331
Низкий

5.9 Medium

CVSS3

Уязвимость CVE-2026-44431