Fedora Account System
Red Hat Associate
Red Hat Customer
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:27929 https://access.redhat.com/errata/RHSA-2026:27929
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:28000 https://access.redhat.com/errata/RHSA-2026:28000
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:28158 https://access.redhat.com/errata/RHSA-2026:28158
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:28159 https://access.redhat.com/errata/RHSA-2026:28159
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:28157 https://access.redhat.com/errata/RHSA-2026:28157
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:32992 https://access.redhat.com/errata/RHSA-2026:32992
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.6 for RHEL 9 Via RHSA-2026:34160 https://access.redhat.com/errata/RHSA-2026:34160
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:36732 https://access.redhat.com/errata/RHSA-2026:36732