CVE-2026-44431
EUVD-2026-3004613.05.2026, 16:16
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| python | urllib3 | 1.23 ≤ 𝑥 < 2.7.0 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python-urllib3 |
| ||||||||||||||||||||||||||||
| python3-urllib3 |
| ||||||||||||||||||||||||||||
| python311-urllib3 |
| ||||||||||||||||||||||||||||
| python311-urllib3_1 |
| ||||||||||||||||||||||||||||
| python36-urllib3 |
|
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Common Weakness Enumeration
Vulnerability Media Exposure