VDB

PYSEC-2018-32

PYSEC-2018-32 PUBLISHED

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

Affected Products

VendorProductVersions
PyPIurllib30, 0.3, 0.4.1

Timeline

  • Dec 11, 2018 CVE Published
  • Nov 8, 2023 CVE Updated
  • May 1, 2026 Distribution Patch
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›