Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20861-1

Опубликовано: 01 июн. 2026
Источник: suse-cvrf

Описание

Security update for python-urllib3

This update for python-urllib3 fixes the following issue

  • CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied low-level redirects (bsc#1265267).

Список пакетов

openSUSE Leap 16.0
python313-urllib3-2.5.0-160000.6.1

Описание

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.


Затронутые продукты
openSUSE Leap 16.0:python313-urllib3-2.5.0-160000.6.1

Ссылки