Bug 2477167 (CVE-2026-44431)

Summary: CVE-2026-44431 urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abarbaro, adinn, alinfoot, alizardo, anpicker, anthomas, aprice, aruklets, bbrownin, bdettelb, brasmith, cahl, caswilli, cmyers, cochase, crizzo, derez, dfreiber, dkeler, dnakabaa, doconnor, dranck, drow, dschmidt, dtrifiro, dymurray, eborisov, eglynn, ehelms, erezende, fdeutsch, fzakkak, galder, ggainey, gtanzill, hasun, ibolton, ilpinto, jburrell, jbuscemi, jchui, jdobes, jfula, jhe, jjoyce, jkoehler, jlanda, jmatthew, jmitchel, jmontleo, jowilson, jpasqual, jpretori, jsamir, jschluet, juwatts, jwong, kaycoth, kbempah, kgaikwad, kshier, ktsao, lball, lbrazdil, lcouzens, lhh, lichen, ljawale, lphiri, ltomasbo, luizcosta, mbabacek, mbarnett, mburns, mgarciac, mhayden, mhulan, mminar, mrunge, msilmser, nboldt, ngough, nmoumoul, nweather, nyancey, oaljalju, oezr, olubyans, omaciel, ometelka, orabin, oramraz, osousa, pakotvan, pcreech, pgaikwad, pjindal, prwatson, psrna, ptisnovs, rbiba, rbobbitt, rbryant, rchan, rhel-process-autobot, rjohnson, sbiarozk, sdoran, sgehwolf, simaishi, slucidi, smallamp, smcdonal, smullick, solenoci, sseago, sskracic, stcannon, sthirugn, stirabos, suppawar, syedriko, teagle, thason, tmalecek, tpfromme, tqvarnst, ttakamiy, veshanka, vimartin, vkumar, watson-tool-maintainers, weaton, xdharmai, xialiu, xiaoxwan, yguenane, ykashtan, zzhou
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in urllib3, an HTTP client library for Python. When using the low-level API via `ProxyManager.connection_from_url().urlopen()` with `assert_same_host=False`, cross-origin redirects can still forward sensitive headers. This could allow a remote attacker to gain unauthorized access to sensitive information.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-05-13 17:02:04 UTC
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

Comment 4 errata-xmlrpc 2026-06-22 14:40:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:27929 https://access.redhat.com/errata/RHSA-2026:27929

Comment 5 errata-xmlrpc 2026-06-22 15:52:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:28000 https://access.redhat.com/errata/RHSA-2026:28000

Comment 6 errata-xmlrpc 2026-06-23 10:17:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:28158 https://access.redhat.com/errata/RHSA-2026:28158

Comment 7 errata-xmlrpc 2026-06-23 10:39:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:28159 https://access.redhat.com/errata/RHSA-2026:28159

Comment 8 errata-xmlrpc 2026-06-23 10:43:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:28157 https://access.redhat.com/errata/RHSA-2026:28157

Comment 9 errata-xmlrpc 2026-06-29 12:24:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:32992 https://access.redhat.com/errata/RHSA-2026:32992

Comment 10 errata-xmlrpc 2026-07-01 11:03:17 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 9

Via RHSA-2026:34160 https://access.redhat.com/errata/RHSA-2026:34160

Comment 11 errata-xmlrpc 2026-07-08 14:06:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:36732 https://access.redhat.com/errata/RHSA-2026:36732

Comment 14 errata-xmlrpc 2026-07-28 12:02:28 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:47092 https://access.redhat.com/errata/RHSA-2026:47092

Comment 15 errata-xmlrpc 2026-07-28 12:02:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:47091 https://access.redhat.com/errata/RHSA-2026:47091

Comment 16 errata-xmlrpc 2026-07-29 01:18:14 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:47126 https://access.redhat.com/errata/RHSA-2026:47126

Comment 17 errata-xmlrpc 2026-07-29 01:18:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:47129 https://access.redhat.com/errata/RHSA-2026:47129

Comment 18 errata-xmlrpc 2026-08-04 09:30:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:49927 https://access.redhat.com/errata/RHSA-2026:49927

Comment 19 errata-xmlrpc 2026-08-06 09:26:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:51045 https://access.redhat.com/errata/RHSA-2026:51045

Comment 20 errata-xmlrpc 2026-08-06 16:33:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:51152 https://access.redhat.com/errata/RHSA-2026:51152

Comment 21 errata-xmlrpc 2026-08-06 16:42:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:51157 https://access.redhat.com/errata/RHSA-2026:51157