Junglewise Threat Intelligence

CVE-2026-55403: koxudaxi datamodel-code-generator credential leak in cross-origin redirects

CVE-2026-55403 · Severity: low · CVSS 3.7 · Published 2026-07-28

Technologies: Koxudaxi Datamodel-Code-Generator, datamodel-code-generator (PyPI). Vendors: Koxudaxi, PyPI.

Executive brief

datamodel-code-generator is a tool used to automatically create Python code from data schema definitions. A security flaw was identified where the tool incorrectly shares sensitive login credentials (such as passwords or session tokens) when it is redirected from a trusted website to a different, potentially malicious website while downloading a schema. This could allow an attacker who controls a schema host to steal credentials intended for a legitimate service.

Technical details

A credential leakage vulnerability exists in the `get_body()` function within `src/datamodel_code_generator/http.py`. The component manually handles HTTP redirects but fails to strip sensitive headers when the redirect target belongs to a different origin (scheme, host, or port). An attacker who can influence the redirect chain—either by compromising a schema host or through an open redirect—can capture `Authorization`, `Cookie`, and `Proxy-Authorization` headers. This occurs when users provide credentials via `--http-headers` or URL userinfo. The issue is resolved in version 0.63.0 by ensuring sensitive headers are dropped during cross-origin redirects.

Affected products

  • koxudaxi datamodel-code-generator <= 0.62.0

Timeline

  • 2026-06-11: patched: Fix merged into main branch
  • 2026-06-12: advisory: GitHub Security Advisory GHSA-r5vv-ff45-prp2 published
  • 2026-07-28: disclosed: CVE-2026-55403 published to NVD

References

Related threats