Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2026-44889

около 1 месяца назад

WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips ASCII tab, carriage return, and newline characters before parsing, so a redirect target containing such characters can be reinterpreted as a protocol-relative URL whose authority is an attacker-controlled host. This bypasses the CVE-2024-42353 fix that escaped a leading double slash, allowing an attacker who influences the redirect location to send users to an arbitrary external site instead of the intended one. This vulnerability is fixed in 1.8.10.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2026-44889

около 1 месяца назад

WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips ASCII tab, carriage return, and newline characters before parsing, so a redirect target containing such characters can be reinterpreted as a protocol-relative URL whose authority is an attacker-controlled host. This bypasses the CVE-2024-42353 fix that escaped a leading double slash, allowing an attacker who influences the redirect location to send users to an arbitrary external site instead of the intended one. This vulnerability is fixed in 1.8.10.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-44889

около 1 месяца назад

WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips ASCII tab, carriage return, and newline characters before parsing, so a redirect target containing such characters can be reinterpreted as a protocol-relative URL whose authority is an attacker-controlled host. This bypasses the CVE-2024-42353 fix that escaped a leading double slash, allowing an attacker who influences the redirect location to send users to an arbitrary external site instead of the intended one. This vulnerability is fixed in 1.8.10.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2026-44889

около 1 месяца назад

WebOb: Location header normalization during redirect leads to open redirect

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2026-44889

около 1 месяца назад

WebOb provides objects for HTTP requests and responses. Prior to 1.8.1 ...

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21063-1

около 1 месяца назад

Security update for python-Markdown, python-joblib, python-handy-archives, python-apache-libcloud, python-WebOb, python-PyGithub, python-soupsieve

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2982-1

22 дня назад

Security update for python-WebOb

EPSS: Низкий
github логотип

GHSA-fh3h-vg37-cc95

2 месяца назад

WebOb: Location header normalization during redirect leads to open redirect - again

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-44889

WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips ASCII tab, carriage return, and newline characters before parsing, so a redirect target containing such characters can be reinterpreted as a protocol-relative URL whose authority is an attacker-controlled host. This bypasses the CVE-2024-42353 fix that escaped a leading double slash, allowing an attacker who influences the redirect location to send users to an arbitrary external site instead of the intended one. This vulnerability is fixed in 1.8.10.

CVSS3: 6.1
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-44889

WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips ASCII tab, carriage return, and newline characters before parsing, so a redirect target containing such characters can be reinterpreted as a protocol-relative URL whose authority is an attacker-controlled host. This bypasses the CVE-2024-42353 fix that escaped a leading double slash, allowing an attacker who influences the redirect location to send users to an arbitrary external site instead of the intended one. This vulnerability is fixed in 1.8.10.

CVSS3: 6.1
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-44889

WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips ASCII tab, carriage return, and newline characters before parsing, so a redirect target containing such characters can be reinterpreted as a protocol-relative URL whose authority is an attacker-controlled host. This bypasses the CVE-2024-42353 fix that escaped a leading double slash, allowing an attacker who influences the redirect location to send users to an arbitrary external site instead of the intended one. This vulnerability is fixed in 1.8.10.

CVSS3: 6.1
0%
Низкий
около 1 месяца назад
msrc логотип
CVE-2026-44889

WebOb: Location header normalization during redirect leads to open redirect

CVSS3: 6.1
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-44889

WebOb provides objects for HTTP requests and responses. Prior to 1.8.1 ...

CVSS3: 6.1
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21063-1

Security update for python-Markdown, python-joblib, python-handy-archives, python-apache-libcloud, python-WebOb, python-PyGithub, python-soupsieve

0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2982-1

Security update for python-WebOb

0%
Низкий
22 дня назад
github логотип
GHSA-fh3h-vg37-cc95

WebOb: Location header normalization during redirect leads to open redirect - again

CVSS3: 6.1
0%
Низкий
2 месяца назад

Уязвимостей на страницу