CVE-2026-44431

Name
CVE-2026-44431
Description
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Mitigation https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:python:urllib3:*:*:*:*:*:*:*:* py3-urllib3 >= 1.23 < 2.7.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
py3-urllib3 edge-main 2.6.3-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 edge-main 2.6.3-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 edge-main 2.6.2-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 edge-main 2.5.0-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 edge-main 1.26.20-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 edge-main 1.26.18-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 edge-main 1.26.17-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 edge-main 1.26.4-r0 None possibly vulnerable
py3-urllib3 edge-main 1.25.9-r0 None possibly vulnerable
py3-urllib3 3.23-main 2.6.3-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 3.23-main 2.5.0-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 3.22-main 1.26.20-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 3.22-main 1.26.20-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 3.22-main 1.26.18-r0 None possibly vulnerable
py3-urllib3 3.22-main 1.26.17-r0 None possibly vulnerable
py3-urllib3 3.22-main 1.26.4-r0 None possibly vulnerable
py3-urllib3 3.22-main 1.25.9-r0 None possibly vulnerable
py3-urllib3 3.21-main 1.26.20-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 3.21-main 1.26.20-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 3.21-main 1.26.18-r0 None possibly vulnerable
py3-urllib3 3.21-main 1.26.17-r0 None possibly vulnerable
py3-urllib3 3.21-main 1.26.4-r0 None possibly vulnerable
py3-urllib3 3.21-main 1.25.9-r0 None possibly vulnerable
py3-urllib3 3.20-main 1.26.18-r2 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 3.20-main 1.26.18-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 3.20-main 1.26.18-r0 None possibly vulnerable
py3-urllib3 3.20-main 1.26.17-r0 None possibly vulnerable
py3-urllib3 3.20-main 1.26.4-r0 None possibly vulnerable
py3-urllib3 3.20-main 1.25.9-r0 None possibly vulnerable
py3-urllib3 3.19-main 1.26.18-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
py3-urllib3 3.19-main 1.26.17-r0 None possibly vulnerable
py3-urllib3 3.19-main 1.26.4-r0 None possibly vulnerable
py3-urllib3 3.19-main 1.25.9-r0 None possibly vulnerable