Junglewise Threat Intelligence

CVE-2026-44431: urllib3 sensitive header leak in ProxyManager low-level redirects

CVE-2026-44431 · Severity: medium · CVSS 5.3 · Published 2026-05-13

Technologies: Urllib3. Vendors: PyPI.

Executive brief

urllib3 is a widely used Python library for making web requests. A security flaw exists where sensitive information, such as login credentials and session cookies, may be unintentionally sent to an untrusted third-party website during a redirect. This could allow an attacker to steal user sessions or authentication tokens if an application uses specific low-level functions of the library.

Technical details

An information exposure vulnerability exists in urllib3's low-level API. When using ProxyManager.connection_from_url().urlopen() with assert_same_host=False, the library fails to strip sensitive headers (Authorization, Cookie, and Proxy-Authorization) during cross-origin redirects. While the high-level request() API correctly handles these redirects by removing headers defined in Retry.DEFAULT_REMOVE_HEADERS_ON_REDIRECT, the low-level flow bypasses these protections. An attacker who can trigger a redirect to a malicious domain could capture these sensitive headers. The issue is resolved in version 2.7.0.

Affected products

  • urllib3 urllib3 >= 1.23, < 2.7.0

Timeline

  • 2026-05-07: advisory: GitHub Security Advisory published
  • 2026-05-13: disclosed: CVE published to NVD
  • 2026-06-26: patched: Debian LTS security update released

References

Related threats