Описание
Security update for python-urllib3_1
This update for python-urllib3_1 fixes the following issue
- CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied low-level redirects (bsc#1265267).
Список пакетов
openSUSE Leap 16.0
python313-urllib3_1-1.26.20-160000.4.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1265267
- SUSE CVE CVE-2026-44431 page
Описание
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
Затронутые продукты
openSUSE Leap 16.0:python313-urllib3_1-1.26.20-160000.4.1
Ссылки
- CVE-2026-44431
- SUSE Bug 1265267