Executive brief
urllib3 is a widely used Python library for making web requests. A security flaw exists where sensitive information, such as login credentials and session cookies, may be unintentionally sent to an untrusted third-party website during a redirect. This could allow an attacker to steal user sessions or authentication tokens if an application uses specific low-level functions of the library.
Technical details
An information exposure vulnerability exists in urllib3's low-level API. When using ProxyManager.connection_from_url().urlopen() with assert_same_host=False, the library fails to strip sensitive headers (Authorization, Cookie, and Proxy-Authorization) during cross-origin redirects. While the high-level request() API correctly handles these redirects by removing headers defined in Retry.DEFAULT_REMOVE_HEADERS_ON_REDIRECT, the low-level flow bypasses these protections. An attacker who can trigger a redirect to a malicious domain could capture these sensitive headers. The issue is resolved in version 2.7.0.
Affected products
- urllib3 urllib3 >= 1.23, < 2.7.0
Timeline
- 2026-05-07: advisory: GitHub Security Advisory published
- 2026-05-13: disclosed: CVE published to NVD
- 2026-06-26: patched: Debian LTS security update released