Описание
Security update for python-urllib3_1
This update for python-urllib3_1 fixes the following issue
- CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied low-level redirects (bsc#1265267).
Список пакетов
SUSE Linux Enterprise Module for Python 3 15 SP7
python311-urllib3_1-1.26.18-150600.3.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS
python311-urllib3_1-1.26.18-150600.3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
python311-urllib3_1-1.26.18-150600.3.9.1
Ссылки
- Link for SUSE-SU-2026:2067-1
- E-Mail link for SUSE-SU-2026:2067-1
- SUSE Security Ratings
- SUSE Bug 1265267
- SUSE CVE CVE-2026-44431 page
Описание
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
Затронутые продукты
SUSE Linux Enterprise Module for Python 3 15 SP7:python311-urllib3_1-1.26.18-150600.3.9.1
SUSE Linux Enterprise Server 15 SP6-LTSS:python311-urllib3_1-1.26.18-150600.3.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6:python311-urllib3_1-1.26.18-150600.3.9.1
Ссылки
- CVE-2026-44431
- SUSE Bug 1265267