8.2 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Attack Requirement (AT): Present (P)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Attack Requirement (MAT): Present (P)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
12 packages
- kodiPackages.urllib3
- python312Packages.types-urllib3
- python313Packages.types-urllib3
- python314Packages.types-urllib3
- python312Packages.urllib3-future
- python313Packages.urllib3-future
- python314Packages.urllib3-future
- python313Packages.lance-namespace-urllib3-client
- python314Packages.lance-namespace-urllib3-client
- python312Packages.opentelemetry-instrumentation-urllib3
- python313Packages.opentelemetry-instrumentation-urllib3
- python314Packages.opentelemetry-instrumentation-urllib3
- @LeSuisse accepted
- @LeSuisse published on GitHub
urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
References
-
https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc x_refsource_CONFIRM
Affected products
- ==>= 1.23, < 2.7.0
Matching in nixpkgs
pkgs.python312Packages.urllib3
Powerful, user-friendly HTTP client for Python
-
nixos-25.11 urllib3-2.5.0
- nixos-25.11-small urllib3-2.5.0
- nixpkgs-25.11-darwin urllib3-2.5.0
pkgs.python313Packages.urllib3
Powerful, user-friendly HTTP client for Python
-
nixos-unstable urllib3-2.6.3
- nixpkgs-unstable urllib3-2.6.3
- nixos-unstable-small urllib3-2.6.3
-
nixos-25.11 urllib3-2.5.0
- nixos-25.11-small urllib3-2.5.0
- nixpkgs-25.11-darwin urllib3-2.5.0
pkgs.python314Packages.urllib3
Powerful, user-friendly HTTP client for Python
-
nixos-unstable urllib3-2.6.3
- nixpkgs-unstable urllib3-2.6.3
- nixos-unstable-small urllib3-2.6.3
Ignored packages (12)
pkgs.kodiPackages.urllib3
HTTP library with thread-safe connection pooling, file post, and more
-
nixos-unstable urllib3-2.2.3
- nixpkgs-unstable urllib3-2.2.3
- nixos-unstable-small urllib3-2.2.3
-
nixos-25.11 urllib3-2.2.3
- nixos-25.11-small urllib3-2.2.3
- nixpkgs-25.11-darwin urllib3-2.2.3
pkgs.python312Packages.types-urllib3
Typing stubs for urllib3
-
nixos-25.11 urllib3-1.26.25.14
- nixos-25.11-small urllib3-1.26.25.14
- nixpkgs-25.11-darwin urllib3-1.26.25.14
pkgs.python313Packages.types-urllib3
Typing stubs for urllib3
-
nixos-unstable urllib3-1.26.25.14
- nixpkgs-unstable urllib3-1.26.25.14
- nixos-unstable-small urllib3-1.26.25.14
-
nixos-25.11 urllib3-1.26.25.14
- nixos-25.11-small urllib3-1.26.25.14
- nixpkgs-25.11-darwin urllib3-1.26.25.14
pkgs.python314Packages.types-urllib3
Typing stubs for urllib3
-
nixos-unstable urllib3-1.26.25.14
- nixpkgs-unstable urllib3-1.26.25.14
- nixos-unstable-small urllib3-1.26.25.14
pkgs.python312Packages.urllib3-future
Powerful HTTP 1.1, 2, and 3 client with both sync and async interfaces
-
nixos-25.11 urllib3-future-2.15.903
- nixos-25.11-small urllib3-future-2.15.903
- nixpkgs-25.11-darwin urllib3-future-2.15.903
pkgs.python313Packages.urllib3-future
Powerful HTTP 1.1, 2, and 3 client with both sync and async interfaces
-
nixos-unstable urllib3-future-2.19.913
- nixpkgs-unstable urllib3-future-2.19.913
- nixos-unstable-small urllib3-future-2.19.913
-
nixos-25.11 urllib3-future-2.15.903
- nixos-25.11-small urllib3-future-2.15.903
- nixpkgs-25.11-darwin urllib3-future-2.15.903
pkgs.python314Packages.urllib3-future
Powerful HTTP 1.1, 2, and 3 client with both sync and async interfaces
-
nixos-unstable urllib3-future-2.19.913
- nixpkgs-unstable urllib3-future-2.19.913
- nixos-unstable-small urllib3-future-2.19.913
pkgs.python313Packages.lance-namespace-urllib3-client
Lance namespace OpenAPI specification
-
nixos-unstable urllib3-client-0.6.1
- nixpkgs-unstable urllib3-client-0.6.1
- nixos-unstable-small urllib3-client-0.7.6
pkgs.python314Packages.lance-namespace-urllib3-client
Lance namespace OpenAPI specification
-
nixos-unstable urllib3-client-0.6.1
- nixpkgs-unstable urllib3-client-0.6.1
- nixos-unstable-small urllib3-client-0.7.6
pkgs.python312Packages.opentelemetry-instrumentation-urllib3
OpenTelemetry urllib3 instrumentation
-
nixos-25.11 urllib3-0.55b0
- nixos-25.11-small urllib3-0.55b0
- nixpkgs-25.11-darwin urllib3-0.55b0
pkgs.python313Packages.opentelemetry-instrumentation-urllib3
OpenTelemetry urllib3 instrumentation
-
nixos-unstable urllib3-0.55b0
- nixpkgs-unstable urllib3-0.55b0
- nixos-unstable-small urllib3-0.55b0
-
nixos-25.11 urllib3-0.55b0
- nixos-25.11-small urllib3-0.55b0
- nixpkgs-25.11-darwin urllib3-0.55b0
pkgs.python314Packages.opentelemetry-instrumentation-urllib3
OpenTelemetry urllib3 instrumentation
-
nixos-unstable urllib3-0.55b0
- nixpkgs-unstable urllib3-0.55b0
- nixos-unstable-small urllib3-0.55b0
Package maintainers
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>