CVE-2023-43804
published 2023-10-04CVE-2023-43804: urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies…
PriorityP344high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
1.21%
64.9th percentile
urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | python-urllib3 | < python-urllib3 1.26.12-1+deb12u1 (bookworm) | python-urllib3 1.26.12-1+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_mozjs_102.15.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-urllib3_2.0.4-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-urllib3_2.0.7-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_python-urllib3_1.26.18-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| paloalto | pan-os | — | — |
| python | urllib3 | < 1.26.17 | 1.26.17 |
| python | urllib3 | >= 2.0.0 < 2.0.6 | 2.0.6 |
| urllib3 | urllib3 | < 1.26.17 | 1.26.17 |
| urllib3 | urllib3 | — | — |
| urllib3 | urllib3 | >= 0 < 1.26.17 | 1.26.17 |
| urllib3 | urllib3 | >= 2.0.0 < 2.0.6 | 2.0.6 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
osv8.1HIGH
vendor_oracle8.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2018-6594 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2023-38546 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (urllib3) — CVE-2023-43804
vendor_oracle·2024-04-15·CVSS 8.1
CVE-2023-43804 [MEDIUM] Oracle Oracle Analytics Risk Matrix: Analytics Server (urllib3) — CVE-2023-43804
Oracle Oracle Analytics Risk Matrix: Analytics Server (urllib3) vulnerability
CVE: CVE-2023-43804
CVSS: 8.1
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Ubuntu
pip vulnerabilities
vendor_ubuntu·2023-11-15·CVSS 6.1
CVE-2023-45803 [MEDIUM] pip vulnerabilities
Title: pip vulnerabilities
Summary: Several security issues were fixed in pip.
USN-6473-1 fixed vulnerabilities in urllib3. This update provides the
corresponding updates for the urllib3 module bundled into pip.
Original advisory details:
It was discovered that urllib3 didn't strip HTTP Authorization header
on cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)
It was discovered that urllib3 didn't strip HTTP Cookie header on
cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-43804)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstanc
Ubuntu
urllib3 vulnerabilities
vendor_ubuntu·2023-11-07·CVSS 6.1
CVE-2023-45803 [MEDIUM] urllib3 vulnerabilities
Title: urllib3 vulnerabilities
Summary: Several security issues were fixed in urllib3.
It was discovered that urllib3 didn't strip HTTP Authorization header
on cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)
It was discovered that urllib3 didn't strip HTTP Cookie header on
cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-43804)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2023-45803)
Instructions: In general, a standard system update
Microsoft
`Cookie` HTTP header isn't stripped on cross-origin redirects
vendor_msrc·2023-10-10·CVSS 5.9
CVE-2023-43804 [MEDIUM] CWE-200 `Cookie` HTTP header isn't stripped on cross-origin redirects
`Cookie` HTTP header isn't stripped on cross-origin redirects
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: h
Red Hat
python-urllib3: Cookie request header isn't stripped during cross-origin redirects
vendor_redhat·2023-10-04·CVSS 5.9
CVE-2023-43804 [MEDIUM] CWE-200 python-urllib3: Cookie request header isn't stripped during cross-origin redirects
python-urllib3: Cookie request header isn't stripped during cross-origin redirects
urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.
A flaw was found in urllib3, a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, which is the responsibility of the user. However, it is possible
Debian
CVE-2023-43804: python-urllib3 - urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat...
vendor_debian·2023·CVSS 5.9
CVE-2023-43804 [MEDIUM] CVE-2023-43804: python-urllib3 - urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat...
urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.
Scope: local
bookworm: resolved (fixed in 1.26.12-1+deb12u1)
bullseye: resolved (fixed in 1.26.5-1~exp1+deb11u1)
forky: resolved (fixed in 1.26.17-1)
sid: resolved (fixed in 1.26.17-1)
trixie: resolved (fixed in 1.26.17-1)
GHSA
Liferay search widget vulnerable to Cross-site Scripting
ghsa·2025-09-17
CVE-2025-43804 [MEDIUM] CWE-79 Liferay search widget vulnerable to Cross-site Scripting
Liferay search widget vulnerable to Cross-site Scripting
There is a Cross-site scripting (XSS) vulnerability in Liferay Portal's Search widget . Versions 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allow remote attackers to inject arbitrary web scripts or HTML via the `_com_liferay_portal_search_web_portlet_SearchPortlet_userId` parameter.
OSV
python-pip vulnerabilities
osv·2023-11-15·CVSS 6.1
CVE-2018-25091 [MEDIUM] python-pip vulnerabilities
python-pip vulnerabilities
USN-6473-1 fixed vulnerabilities in urllib3. This update provides the
corresponding updates for the urllib3 module bundled into pip.
Original advisory details:
It was discovered that urllib3 didn't strip HTTP Authorization header
on cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)
It was discovered that urllib3 didn't strip HTTP Cookie header on
cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-43804)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstances. A remote attacker could
possibly use this issue t
OSV
python-urllib3 vulnerabilities
osv·2023-11-07·CVSS 6.1
CVE-2018-25091 [MEDIUM] python-urllib3 vulnerabilities
python-urllib3 vulnerabilities
It was discovered that urllib3 didn't strip HTTP Authorization header
on cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)
It was discovered that urllib3 didn't strip HTTP Cookie header on
cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-43804)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2023-45803)
OSV
CVE-2023-43804: urllib3 is a user-friendly HTTP client library for Python
osv·2023-10-04·CVSS 8.1
CVE-2023-43804 [HIGH] CVE-2023-43804: urllib3 is a user-friendly HTTP client library for Python
urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.
OSV
`Cookie` HTTP header isn't stripped on cross-origin redirects
osv·2023-10-02
CVE-2023-43804 [HIGH] `Cookie` HTTP header isn't stripped on cross-origin redirects
`Cookie` HTTP header isn't stripped on cross-origin redirects
urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly.
Users **must** handle redirects themselves instead of relying on urllib3's automatic redirects to achieve safe processing of the `Cookie` header, thus we decided to strip the header by default in order to further protect users who aren't using the correct approach.
## Affected usages
We believe the number of usages affected by this advisory is low. It requires all of the following to be true
GHSA
`Cookie` HTTP header isn't stripped on cross-origin redirects
ghsa·2023-10-02
CVE-2023-43804 [HIGH] CWE-200 `Cookie` HTTP header isn't stripped on cross-origin redirects
`Cookie` HTTP header isn't stripped on cross-origin redirects
urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly.
Users **must** handle redirects themselves instead of relying on urllib3's automatic redirects to achieve safe processing of the `Cookie` header, thus we decided to strip the header by default in order to further protect users who aren't using the correct approach.
## Affected usages
We believe the number of usages affected by this advisory is low. It requires all of the following to be true
No detection rules found.
No public exploits indexed.
https://github.com/urllib3/urllib3/commit/01220354d389cd05474713f8c982d05c9b17aafbhttps://github.com/urllib3/urllib3/commit/644124ecd0b6e417c527191f866daa05a5a2056dhttps://github.com/urllib3/urllib3/security/advisories/GHSA-v845-jxx5-vc9fhttps://lists.debian.org/debian-lts-announce/2023/10/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/https://lists.fedoraproject.org/archives/list/[email protected]/message/I3PR7C6RJ6JUBQKIJ644DMIJSUP36VDY/https://lists.fedoraproject.org/archives/list/[email protected]/message/NDAGZXYJ7H2G3SB47M453VQVNAWKAEJJ/https://github.com/urllib3/urllib3/commit/01220354d389cd05474713f8c982d05c9b17aafbhttps://github.com/urllib3/urllib3/commit/644124ecd0b6e417c527191f866daa05a5a2056dhttps://github.com/urllib3/urllib3/security/advisories/GHSA-v845-jxx5-vc9fhttps://lists.debian.org/debian-lts-announce/2023/10/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2024/12/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/https://lists.fedoraproject.org/archives/list/[email protected]/message/I3PR7C6RJ6JUBQKIJ644DMIJSUP36VDY/https://lists.fedoraproject.org/archives/list/[email protected]/message/NDAGZXYJ7H2G3SB47M453VQVNAWKAEJJ/https://security.netapp.com/advisory/ntap-20241213-0007/https://www.vicarius.io/vsociety/posts/cve-2023-43804-urllib3-vulnerability-3
2023-10-04
Published