cbcvebase.
CVE-2026-44431
published 2026-05-13

CVE-2026-44431: urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via…

high8.2CVSS 4.0
AVNACHATPPRNUINVCHVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

Affected

139 ranges· showing 25
VendorProductVersion rangeFixed in
ansible-automation-platform-24lightspeed-rhel8
ansible-automation-platform-25ee-supported-rhel8
ansible-automation-platform-25lightspeed-chatbot-rhel8
ansible-automation-platform-25lightspeed-rhel8
ansible-automation-platform-26controller-rhel9
ansible-automation-platform-26controller-rhel9-operator
ansible-automation-platform-26de-minimal-rhel9
ansible-automation-platform-26de-supported-rhel9
ansible-automation-platform-26eda-controller-rhel9
ansible-automation-platform-26eda-controller-rhel9-operator
ansible-automation-platform-26ee-minimal-rhel9
ansible-automation-platform-26ee-supported-rhel9
ansible-automation-platform-26gateway-rhel9
ansible-automation-platform-26gateway-rhel9-operator
ansible-automation-platform-26hub-rhel9
ansible-automation-platform-26hub-rhel9-operator
ansible-automation-platform-26lightspeed-chatbot-rhel9
ansible-automation-platform-26lightspeed-rhel9
ansible-automation-platform-26lightspeed-rhel9-operator
ansible-automation-platform-26platform-resource-rhel9-operator
ansible-automation-platform-26platform-resource-runner-rhel9
ansible-automation-platform-tech-previewmetrics-service-rhel9
ansible-automation-platform-tech-previewmetrics-service-rhel9-operator
ansible-automation-platformautomation-dashboard-rhel9
aquasecuritytrivy