CVE-2026-44889

EUVD-2026-38391
WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips ASCII tab, carriage return, and newline characters before parsing, so a redirect target containing such characters can be reinterpreted as a protocol-relative URL whose authority is an attacker-controlled host. This bypasses the CVE-2024-42353 fix that escaped a leading double slash, allowing an attacker who influences the redirect location to send users to an arbitrary external site instead of the intended one. This vulnerability is fixed in 1.8.10.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 5.79%
Affected Products (NVD)
VendorProductVersion
pylonsprojectwebob
𝑥
< 1.8.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-webob
bookworm
postponed
bullseye
postponed
forky
1:1.8.10-1
fixed
sid
1:1.8.10-1
fixed
trixie
1:1.8.10-0+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-webob
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
python-webob
Azure Linux 3.0
0:1.8.10-1.azl3
fixed