<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:00:42 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-54770 — WebOb: Open redirect in Location header normalization via leading C0 control / space characters</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-54770</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Pylons webob&lt;/p&gt;
&lt;p&gt;WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An attacker-controlled value such as a space followed by a protocol-relative or absolute URL can therefore bypass SCHEME_RE and startswith(&amp;#34;//&amp;#34;) checks and be normalized to an off-host redirect. Request.relative_url() and webob.exc._HTTPMove subclasses, including HTTPFound, are also affected because they use the same unsafe URL joining behavior or bypass the earlier normalization path. An unauthenticated attacker who can influence an application&amp;#39;s redirect target can send users to an attacker-controlled host for phishing or OAuth and SSO token theft, but exploitation requires the user to follow the redirect. This issue is fixed in version 1.8.11.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Pylons webob&lt;/p&gt;
&lt;p&gt;WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An attacker-controlled value such as a space followed by a protocol-relative or absolute URL can therefore bypass SCHEME_RE and startswith(&amp;#34;//&amp;#34;) checks and be normalized to an off-host redirect. Request.relative_url() and webob.exc._HTTPMove subclasses, including HTTPFound, are also affected because they use the same unsafe URL joining behavior or bypass the earlier normalization path. An unauthenticated attacker who can influence an application&amp;#39;s redirect target can send users to an attacker-controlled host for phishing or OAuth and SSO token theft, but exploitation requires the user to follow the redirect. This issue is fixed in version 1.8.11.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-54770</guid>
    </item>
    <item>
      <title>GHSA-6hx8-3wjj-gr8g — WebOb: Open redirect in Location header normalization via leading C0 control / space characters</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6hx8-3wjj-gr8g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: webob&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;This is a third follow-up to **CVE-2024-42353 / GHSA-mg3v-6m49-jhp3**
and **CVE-2026-44889 / GHSA-fh3h-vg37-cc95**.&lt;/p&gt;
&lt;p&gt;WebOb makes the `Location` header absolute when it serves a redirect. To stop a
relative or protocol-relative target from redirecting users off-host, it checks
the value for a URI scheme and for a leading `//`, then joins it against the
request URI with `urllib.parse.urljoin()`. The previous fix additionally stripped
ASCII tab/CR/LF from the value before those checks.&lt;/p&gt;
&lt;p&gt;However, on Python 3.10+ `urllib.parse.urljoin()` (via `urlsplit()`) does more
than remove tab/CR/LF: **it also strips leading and trailing C0 control
characters (`U+0000`–`U+001F`) and spaces from the URL before parsing it.**
Because WebOb&amp;#39;s guard checks (`SCHEME_RE` and `startswith(&amp;#34;//&amp;#34;)`) run against the
*un-stripped* value, a single leading space or control byte slips past them, and
`urljoin()` then silently removes that byte and parses what remains as a
protocol-relative — or even absolute — URL. The result is an open redirect to an
attacker-controlled host.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`Response._make_location_absolute()` (in `src/webob/response.py`) performed,
prior to the fix:&lt;/p&gt;
&lt;p&gt;```python
value = value.replace(&amp;#34;\t&amp;#34;, &amp;#34;&amp;#34;).replace(&amp;#34;\r&amp;#34;, &amp;#34;&amp;#34;).replace(&amp;#34;\n&amp;#34;, &amp;#34;&amp;#34;)&lt;/p&gt;
&lt;p&gt;if SCHEME_RE.search(value):          # ^[a-z]+:   -&amp;gt; already absolute, return as-is
    return value&lt;/p&gt;
&lt;p&gt;if value.startswith(&amp;#34;//&amp;#34;):           # neutralize protocol-relative URLs
    value = f&amp;#34;/%2f{value[2:]}&amp;#34;&lt;/p&gt;
&lt;p&gt;new_location = urlparse.urljoin(_…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: webob&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;This is a third follow-up to **CVE-2024-42353 / GHSA-mg3v-6m49-jhp3**
and **CVE-2026-44889 / GHSA-fh3h-vg37-cc95**.&lt;/p&gt;
&lt;p&gt;WebOb makes the `Location` header absolute when it serves a redirect. To stop a
relative or protocol-relative target from redirecting users off-host, it checks
the value for a URI scheme and for a leading `//`, then joins it against the
request URI with `urllib.parse.urljoin()`. The previous fix additionally stripped
ASCII tab/CR/LF from the value before those checks.&lt;/p&gt;
&lt;p&gt;However, on Python 3.10+ `urllib.parse.urljoin()` (via `urlsplit()`) does more
than remove tab/CR/LF: **it also strips leading and trailing C0 control
characters (`U+0000`–`U+001F`) and spaces from the URL before parsing it.**
Because WebOb&amp;#39;s guard checks (`SCHEME_RE` and `startswith(&amp;#34;//&amp;#34;)`) run against the
*un-stripped* value, a single leading space or control byte slips past them, and
`urljoin()` then silently removes that byte and parses what remains as a
protocol-relative — or even absolute — URL. The result is an open redirect to an
attacker-controlled host.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;`Response._make_location_absolute()` (in `src/webob/response.py`) performed,
prior to the fix:&lt;/p&gt;
&lt;p&gt;```python
value = value.replace(&amp;#34;\t&amp;#34;, &amp;#34;&amp;#34;).replace(&amp;#34;\r&amp;#34;, &amp;#34;&amp;#34;).replace(&amp;#34;\n&amp;#34;, &amp;#34;&amp;#34;)&lt;/p&gt;
&lt;p&gt;if SCHEME_RE.search(value):          # ^[a-z]+:   -&amp;gt; already absolute, return as-is
    return value&lt;/p&gt;
&lt;p&gt;if value.startswith(&amp;#34;//&amp;#34;):           # neutralize protocol-relative URLs
    value = f&amp;#34;/%2f{value[2:]}&amp;#34;&lt;/p&gt;
&lt;p&gt;new_location = urlparse.urljoin(_…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6hx8-3wjj-gr8g</guid>
    </item>
  </channel>
</rss>
