CVE-2026-44431
ADVISORY - githubSummary
Impact
When following cross-origin redirects for requests made using urllib3’s high-level APIs, such as urllib3.request(), PoolManager.request(), and ProxyManager.request(), sensitive headers — Authorization, Cookie, and Proxy-Authorization (defined in Retry.DEFAULT_REMOVE_HEADERS_ON_REDIRECT) — are stripped by default, as expected.
However, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers.
Affected usage
Applications and libraries using urllib3 versions earlier than 2.7.0 may be affected if they allow cross-origin redirects while making requests through HTTPConnection.urlopen() instances created via ProxyManager.connection_from_url().
Remediation
Upgrade to urllib3 version 2.7.0 or later, in which sensitive headers are stripped from redirects followed by HTTPConnection.
If upgrading is not immediately possible, avoid using this low-level redirect flow for cross-origin redirects. If appropriate for your use case, switch to ProxyManager.request().
Common Weakness Enumeration (CWE)
Exposure of Sensitive Information to an Unauthorized Actor
Exposure of Sensitive Information to an Unauthorized Actor
NIST
3.9
CVSS SCORE
8.2highGitHub
3.9
CVSS SCORE
8.2highAlpine
-
Debian
-
Ubuntu
3.9
CVSS SCORE
5.3mediumPypA
PYSEC-2026-141
3.9
CVSS SCORE
5.3mediumAlma
-
CVSS SCORE
N/AhighAlma
-
CVSS SCORE
N/AhighAlma
-
CVSS SCORE
N/AhighAlma
-
CVSS SCORE
N/AhighAmazon
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AmediumAmazon
-
CVSS SCORE
N/AmediumRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighRocky
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighOracle
-
CVSS SCORE
N/AhighChainguard
CGA-c7jq-4mq6-p587
-
minimos
MINI-3xgc-53cx-ff5f
-
minimos
MINI-76w6-v44w-v7h2
-
minimos
MINI-84hp-38gr-rfh3
-
minimos
MINI-8qx6-49gc-px7w
-
minimos
MINI-92cw-2ghh-pmc6
-
minimos
MINI-94wh-7573-89j9
-
minimos
MINI-cpjh-v7g2-m78j
-
minimos
MINI-cq9q-52qr-4gx6
-
minimos
MINI-gq25-6xcx-cgq4
-
minimos
MINI-jh59-7mfp-3w3r
-
minimos
MINI-jrcj-3f3v-jhhf
-
minimos
MINI-mmr8-mqh6-2gjw
-
minimos
MINI-p78w-wrc3-6px4
-
minimos
MINI-q3qg-9x57-28hh
-
minimos
MINI-qpwf-cf8r-jrff
-
minimos
MINI-v36v-6m24-79r2
-
minimos
MINI-x462-8h5j-whjm
-
minimos
MINI-xhwv-w54c-3gmc
-
minimos
MINI-xrx5-m4gh-h4vh
-
minimos
MINI-xv59-x34r-45gm
-