PT-2026-39665 · Pypi+3 · Urllib3+3

·

CVE-2026-44431

·

Published

2026-05-07

·

Updated

2026-07-13

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions urllib3 versions 1.23 through 2.6.x
Description Sensitive headers, specifically Authorization, Cookie, and Proxy-Authorization, are forwarded during cross-origin redirects when using the low-level API via ProxyManager.connection from url().urlopen(..., assert same host=False). While high-level APIs like urllib3.request(), PoolManager.request(), and ProxyManager.request() strip these headers by default, the low-level flow fails to do so.
Recommendations Upgrade to version 2.7.0 or later. Avoid using the low-level redirect flow for cross-origin redirects or switch to ProxyManager.request().

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:27929
ALSA-2026:28000
ALSA-2026:28157
ALSA-2026:28158
ALSA-2026:28159
ALSA-2026:32992
ALSA-2026:36732
BDU:2026-09265
CLEANSTART-2026-AN27706
CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EM82280
CLEANSTART-2026-EP51501
CLEANSTART-2026-FT24360
CLEANSTART-2026-GH89210
CLEANSTART-2026-HZ86045
CLEANSTART-2026-IR98353
CLEANSTART-2026-LJ72726
CLEANSTART-2026-LZ07533
CLEANSTART-2026-MR94452
CLEANSTART-2026-MV15822
CLEANSTART-2026-NL78203
CLEANSTART-2026-NN42198
CLEANSTART-2026-QK55639
CLEANSTART-2026-SO50412
CLEANSTART-2026-UO85049
CLEANSTART-2026-UV23635
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CLEANSTART-2026-ZI38454
CVE-2026-44431
ECHO-4544-3B20-7E41
GHSA-QCCP-GFCP-XXVC
OESA-2026-2298
OESA-2026-2299
OESA-2026-2300
OESA-2026-2390
OESA-2026-2391
OESA-2026-2541
OESA-2026-2542
OESA-2026-2543
OESA-2026-2544
OPENSUSE-SU-2026:10838-1
OPENSUSE-SU-2026:20861-1
OPENSUSE-SU-2026:20871-1
PYSEC-2026-141
RHSA-2026:24000
RHSA-2026:24009
RHSA-2026:24014
RHSA-2026:24069
RHSA-2026:25039
RHSA-2026:27929
RHSA-2026:28000
RHSA-2026:28157
RHSA-2026:28158
RHSA-2026:28159
RHSA-2026:30169
RHSA-2026:32992
RHSA-2026:34119
RHSA-2026:34160
RHSA-2026:35111
RHSA-2026:36732
RHSA-2026:37094
RHSA-2026:7634
SUSE-SU-2026:2065-1
SUSE-SU-2026:2067-1
SUSE-SU-2026:2119-1
SUSE-SU-2026:21728-1
SUSE-SU-2026:21741-1
SUSE-SU-2026:21955-1
SUSE-SU-2026:22003-1
SUSE-SU-2026:22011-1
SUSE-SU-2026:2486-1
USN-8379-1

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Urllib3