CVE-2023-45803
published 2023-10-17CVE-2023-45803: urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status…
PriorityP420medium4.2CVSS 3.1
AVAACHPRHUINSUCHINAN
EPSS
0.54%
42.0th percentile
urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensitive data in HTTP request bodies, if this is the case then this vulnerability isn't exploitable. Both of the following conditions must be true to be affected by this vulnerability: 1. Using urllib3 and submitting sensitive information in the HTTP request body (such as form data or JSON) and 2. The origin service is compromised and starts redirecting using 301, 302, or 303 to a malicious peer or the redirected-to service becomes compromised. This issue has been addressed in versions 1.26.18 and 2.0.7 and users are advised to update to resolve this issue. Users unable to update should disable redirects for services that aren't expecting to respond with redirects with `redirects=False` and disable automatic redirects with `redirects=False` and handle 301, 302, and 303 redirects manually by stripping the HTTP request body.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-urllib3 | < python-urllib3 1.26.12-1+deb12u1 (bookworm) | python-urllib3 1.26.12-1+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | azl3_mozjs_102.15.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-pip_24.0-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-pip_24.2-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-urllib3_2.0.4-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-urllib3_2.0.7-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.3-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_python-urllib3_1.26.18-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| python | urllib3 | < 1.26.18 | 1.26.18 |
| python | urllib3 | >= 2.0.0 < 2.0.7 | 2.0.7 |
| urllib3 | urllib3 | < 1.26.18 | 1.26.18 |
| urllib3 | urllib3 | — | — |
| urllib3 | urllib3 | >= 0 < 1.26.18 | 1.26.18 |
| urllib3 | urllib3 | >= 2.0.0 < 2.0.7 | 2.0.7 |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian4.2MEDIUM
vendor_msrc4.2MEDIUM
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
pip vulnerabilities
vendor_ubuntu·2025-09-23·CVSS 6.1
CVE-2023-45803 [MEDIUM] pip vulnerabilities
Title: pip vulnerabilities
Summary: Several security issues were fixed in pip.
Dennis Brinkrolf and Tobias Funke discovered that Requests incorrectly
leaked Proxy-Authorization headers. A remote attacker could possibly use
this issue to obtain sensitive information. This update addresses the issue
in the Requests module bundled into pip in Ubuntu 22.04 LTS.
(CVE-2023-32681)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. This update
addresses the issue in the urllib3 module bundled into pip in Ubuntu
24.04 LTS. (CVE-2023-45803)
Guido Vranken discovered that idna did not properly manage certain inputs,
which could lead to significant resource c
Ubuntu
pip vulnerabilities
vendor_ubuntu·2023-11-15·CVSS 6.1
CVE-2023-45803 [MEDIUM] pip vulnerabilities
Title: pip vulnerabilities
Summary: Several security issues were fixed in pip.
USN-6473-1 fixed vulnerabilities in urllib3. This update provides the
corresponding updates for the urllib3 module bundled into pip.
Original advisory details:
It was discovered that urllib3 didn't strip HTTP Authorization header
on cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)
It was discovered that urllib3 didn't strip HTTP Cookie header on
cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-43804)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstanc
Ubuntu
urllib3 vulnerabilities
vendor_ubuntu·2023-11-07·CVSS 6.1
CVE-2023-45803 [MEDIUM] urllib3 vulnerabilities
Title: urllib3 vulnerabilities
Summary: Several security issues were fixed in urllib3.
It was discovered that urllib3 didn't strip HTTP Authorization header
on cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)
It was discovered that urllib3 didn't strip HTTP Cookie header on
cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-43804)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2023-45803)
Instructions: In general, a standard system update
Red Hat
urllib3: Request body not stripped after redirect from 303 status changes request method to GET
vendor_redhat·2023-10-13·CVSS 4.2
CVE-2023-45803 [MEDIUM] CWE-200 urllib3: Request body not stripped after redirect from 303 status changes request method to GET
urllib3: Request body not stripped after redirect from 303 status changes request method to GET
urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believ
Microsoft
Request body not stripped after redirect in urllib3
vendor_msrc·2023-10-10·CVSS 4.2
CVE-2023-45803 [MEDIUM] CWE-200 Request body not stripped after redirect in urllib3
Request body not stripped after redirect in urllib3
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://lea
Debian
CVE-2023-45803: python-urllib3 - urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wo...
vendor_debian·2023·CVSS 4.2
CVE-2023-45803 [MEDIUM] CVE-2023-45803: python-urllib3 - urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wo...
urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensit
OSV
python-pip vulnerabilities
osv·2025-09-23·CVSS 6.1
CVE-2023-32681 [MEDIUM] python-pip vulnerabilities
python-pip vulnerabilities
Dennis Brinkrolf and Tobias Funke discovered that Requests incorrectly
leaked Proxy-Authorization headers. A remote attacker could possibly use
this issue to obtain sensitive information. This update addresses the issue
in the Requests module bundled into pip in Ubuntu 22.04 LTS.
(CVE-2023-32681)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. This update
addresses the issue in the urllib3 module bundled into pip in Ubuntu
24.04 LTS. (CVE-2023-45803)
Guido Vranken discovered that idna did not properly manage certain inputs,
which could lead to significant resource consumption. An attacker could
possibly use this issue
OSV
python-pip vulnerabilities
osv·2023-11-15·CVSS 6.1
CVE-2018-25091 [MEDIUM] python-pip vulnerabilities
python-pip vulnerabilities
USN-6473-1 fixed vulnerabilities in urllib3. This update provides the
corresponding updates for the urllib3 module bundled into pip.
Original advisory details:
It was discovered that urllib3 didn't strip HTTP Authorization header
on cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)
It was discovered that urllib3 didn't strip HTTP Cookie header on
cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-43804)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstances. A remote attacker could
possibly use this issue t
OSV
python-urllib3 vulnerabilities
osv·2023-11-07·CVSS 6.1
CVE-2018-25091 [MEDIUM] python-urllib3 vulnerabilities
python-urllib3 vulnerabilities
It was discovered that urllib3 didn't strip HTTP Authorization header
on cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-25091)
It was discovered that urllib3 didn't strip HTTP Cookie header on
cross-origin redirects. A remote attacker could possibly use this
issue to obtain sensitive information. (CVE-2023-43804)
It was discovered that urllib3 didn't strip HTTP body on status code
303 redirects under certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. (CVE-2023-45803)
GHSA
urllib3's request body not stripped after redirect from 303 status changes request method to GET
ghsa·2023-10-17
CVE-2023-45803 [MEDIUM] CWE-200 urllib3's request body not stripped after redirect from 303 status changes request method to GET
urllib3's request body not stripped after redirect from 303 status changes request method to GET
urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 303 "See Other" after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although the behavior of removing the request body is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers.
From [RFC 9110 Section 9.3.1](https://www.rfc-editor.org/rfc/rfc9110.html#name-get):
> A client SHOULD NOT generate content in a GET request unless it is made directly to
OSV
urllib3's request body not stripped after redirect from 303 status changes request method to GET
osv·2023-10-17
CVE-2023-45803 [MEDIUM] urllib3's request body not stripped after redirect from 303 status changes request method to GET
urllib3's request body not stripped after redirect from 303 status changes request method to GET
urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 303 "See Other" after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although the behavior of removing the request body is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers.
From [RFC 9110 Section 9.3.1](https://www.rfc-editor.org/rfc/rfc9110.html#name-get):
> A client SHOULD NOT generate content in a GET request unless it is made directly to
OSV
CVE-2023-45803: urllib3 is a user-friendly HTTP client library for Python
osv·2023-10-17·CVSS 4.2
CVE-2023-45803 [MEDIUM] CVE-2023-45803: urllib3 is a user-friendly HTTP client library for Python
urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified in the section for redirects, it can be inferred by piecing together information from different sections and we have observed the behavior in other major HTTP client implementations like curl and web browsers. Because the vulnerability requires a previously trusted service to become compromised in order to have an impact on confidentiality we believe the exploitability of this vulnerability is low. Additionally, many users aren't putting sensit
No detection rules found.
No public exploits indexed.
https://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4https://lists.fedoraproject.org/archives/list/[email protected]/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB/https://lists.fedoraproject.org/archives/list/[email protected]/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/https://lists.fedoraproject.org/archives/list/[email protected]/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX/https://www.rfc-editor.org/rfc/rfc9110.html#name-gethttps://github.com/urllib3/urllib3/commit/4e98d57809dacab1cbe625fddeec1a290c478ea9https://github.com/urllib3/urllib3/security/advisories/GHSA-g4mx-q9vg-27p4https://lists.debian.org/debian-lts-announce/2024/12/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/4R2Y5XK3WALSR3FNAGN7JBYV2B343ZKB/https://lists.fedoraproject.org/archives/list/[email protected]/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5/https://lists.fedoraproject.org/archives/list/[email protected]/message/PPDPLM6UUMN55ESPQWJFLLIZY4ZKCNRX/https://www.rfc-editor.org/rfc/rfc9110.html#name-get
2023-10-17
Published