Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2067-1

Опубликовано: 26 мая 2026
Источник: suse-cvrf

Описание

Security update for python-urllib3_1

This update for python-urllib3_1 fixes the following issue

  • CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied low-level redirects (bsc#1265267).

Список пакетов

SUSE Linux Enterprise Module for Python 3 15 SP7
python311-urllib3_1-1.26.18-150600.3.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS
python311-urllib3_1-1.26.18-150600.3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
python311-urllib3_1-1.26.18-150600.3.9.1

Описание

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.


Затронутые продукты
SUSE Linux Enterprise Module for Python 3 15 SP7:python311-urllib3_1-1.26.18-150600.3.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS:python311-urllib3_1-1.26.18-150600.3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6:python311-urllib3_1-1.26.18-150600.3.9.1

Ссылки