<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T02:52:59.457028+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:27929</id>
    <title>ALSA-2026:27929 — Important: python3.14-urllib3 security update</title>
    <updated>2026-10-04T02:53:07.000063+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: python3.14-urllib3</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* urllib3: urllib3: Denial of Service due to excessive HTTP response decompression (CVE-2026-44432)
  * urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers (CVE-2026-44431)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:27929"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-09265</id>
    <title>bdu:2026-09265</title>
    <updated>2026-10-04T02:53:07.000178+00:00</updated>
    <content>bdu:2026-09265</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-09265"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-44431</id>
    <title>BELL-CVE-2026-44431</title>
    <updated>2026-10-04T02:53:07.000196+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: py3-pip, Alpaquita:23: py3-urllib3, Alpaquita:25: py3-pip, Alpaquita:25: py3-urllib3, Alpaquita:stream: py3-pip, Alpaquita:stream: py3-urllib3, BellSoft Hardened Containers:23: py3-pip, BellSoft Hardened Containers:25: py3-pip, BellSoft Hardened Containers:stream: py3-pip</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-44431"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-abi3audit-cve-2026-44431</id>
    <title>BREW-abi3audit-CVE-2026-44431 — urllib3: Sensitive headers forwarded across origins in proxied low-level redirects</title>
    <updated>2026-10-04T02:53:07.000228+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: abi3audit</p>
<p>### Impact</p>
<p>When following cross-origin redirects for requests made using urllib3’s high-level APIs, such as `urllib3.request()`, `PoolManager.request()`, and `ProxyManager.request()`, sensitive headers — `Authorization`, `Cookie`, and `Proxy-Authorization` (defined in `Retry.DEFAULT_REMOVE_HEADERS_ON_REDIRECT`) — are stripped by default, as expected.</p>
<p>However, cross-origin redirects followed from the low-level API via `ProxyManager.connection_from_url().urlopen(..., assert_same_host=False)` still forward these sensitive headers.</p>
<p>### Affected usage</p>
<p>Applications and libraries using urllib3 versions earlier than 2.7.0 may be affected if they allow cross-origin redirects while making requests through `HTTPConnection.urlopen()` instances created via `ProxyManager.connection_from_url()`.</p>
<p>### Remediation</p>
<p>Upgrade to urllib3 version 2.7.0 or later, in which sensitive headers are stripped from redirects followed by `HTTPConnection`.</p>
<p>If upgrading is not immediately possible, avoid using this low-level redirect flow for cross-origin redirects. If appropriate for your use case, switch to `ProxyManager.request()`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-abi3audit-cve-2026-44431"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0623</id>
    <title>certfr-2026-avi-0623 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T02:53:07.000270+00:00</updated>
    <content>certfr-2026-avi-0623</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0623"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-ae28044</id>
    <title>Withdrawn: CLEANSTART-2026-AE28044 — Security fixes in jupyterhub-k8s-hub 4.3.2-r3</title>
    <updated>2026-10-04T02:53:07.000287+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: jupyterhub-k8s-hub</p>
<p>Package jupyterhub-k8s-hub version 4.3.2-r3 fixes 2 vulnerabilities: CVE-2026-44432, CVE-2026-44431</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-ae28044"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-330522</id>
    <title>EUVD-2026-330522</title>
    <updated>2026-10-04T02:53:07.000332+00:00</updated>
    <content>EUVD-2026-330522</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-330522"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44431</id>
    <title>fkie_cve-2026-44431</title>
    <updated>2026-10-04T02:53:07.000358+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44431"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qccp-gfcp-xxvc</id>
    <title>GHSA-qccp-gfcp-xxvc — urllib3: Sensitive headers forwarded across origins in proxied low-level redirects</title>
    <updated>2026-10-04T02:53:07.000380+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: urllib3</p>
<p>### Impact</p>
<p>When following cross-origin redirects for requests made using urllib3’s high-level APIs, such as `urllib3.request()`, `PoolManager.request()`, and `ProxyManager.request()`, sensitive headers — `Authorization`, `Cookie`, and `Proxy-Authorization` (defined in `Retry.DEFAULT_REMOVE_HEADERS_ON_REDIRECT`) — are stripped by default, as expected.</p>
<p>However, cross-origin redirects followed from the low-level API via `ProxyManager.connection_from_url().urlopen(..., assert_same_host=False)` still forward these sensitive headers.</p>
<p>### Affected usage</p>
<p>Applications and libraries using urllib3 versions earlier than 2.7.0 may be affected if they allow cross-origin redirects while making requests through `HTTPConnection.urlopen()` instances created via `ProxyManager.connection_from_url()`.</p>
<p>### Remediation</p>
<p>Upgrade to urllib3 version 2.7.0 or later, in which sensitive headers are stripped from redirects followed by `HTTPConnection`.</p>
<p>If upgrading is not immediately possible, avoid using this low-level redirect flow for cross-origin redirects. If appropriate for your use case, switch to `ProxyManager.request()`.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qccp-gfcp-xxvc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-44431</id>
    <title>msrc_CVE-2026-44431 — urllib3: Sensitive headers forwarded across origins in proxied low-level redirects</title>
    <updated>2026-10-04T02:53:07.000411+00:00</updated>
    <content>msrc_CVE-2026-44431</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-44431"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2298</id>
    <title>OESA-2026-2298 — python-urllib3 security update</title>
    <updated>2026-10-04T02:53:07.000427+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-urllib3</p>
<p>HTTP library with thread-safe connection pooling, file post support, sanity friendly, and more.

Security Fix(es):</p>
<p>urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.(CVE-2026-44431)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10838-1</id>
    <title>openSUSE-SU-2026:10838-1 — python311-urllib3_1-1.26.20-6.1 on GA media</title>
    <updated>2026-10-04T02:53:07.000447+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-urllib3_1-1.26.20-6.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10838-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-141</id>
    <title>PYSEC-2026-141</title>
    <updated>2026-10-04T02:53:07.000462+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: urllib3</p>
<p>urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-141"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:24009</id>
    <title>RHSA-2026:24009 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-04T02:53:07.000479+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3: urllib3: Denial of Service due to excessive HTTP response decompression</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:24009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:27929</id>
    <title>RLSA-2026:27929 — Important: python3.14-urllib3 security update</title>
    <updated>2026-10-04T02:53:07.000495+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: python3.14-urllib3</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* urllib3: urllib3: Denial of Service due to excessive HTTP response decompression (CVE-2026-44432)</p>
<p>* urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers (CVE-2026-44431)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:27929"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:2065-1</id>
    <title>SUSE-SU-2026:2065-1 — Security update for python-urllib3</title>
    <updated>2026-10-04T02:53:07.000518+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-urllib3</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:2065-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44431</id>
    <title>UBUNTU-CVE-2026-44431</title>
    <updated>2026-10-04T02:53:07.000532+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: python-pip, Ubuntu:Pro:14.04:LTS: python-urllib3, Ubuntu:Pro:16.04:LTS: python-urllib3, Ubuntu:Pro:16.04:LTS: python-pip, Ubuntu:Pro:18.04:LTS: python-urllib3, Ubuntu:Pro:18.04:LTS: python-pip, Ubuntu:Pro:20.04:LTS: python-urllib3, Ubuntu:Pro:20.04:LTS: python-pip, Ubuntu:22.04:LTS: python-urllib3, Ubuntu:Pro:22.04:LTS: python-pip and 6 more</p>
<p>urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44431"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1923</id>
    <title>WID-SEC-W-2026-1923 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-04T02:53:07.000571+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Informationen offenzulegen, Daten zu manipulieren und einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1923"/>
  </entry>
</feed>
