Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86862.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-86862
Upstream
Published
2026-05-13T16:16:57Z
Modified
2026-09-16T06:39:01Z
Summary
CVE-2026-44431 affecting package python-urllib3 for versions less than 2.0.7-5
Details

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

References

Affected packages

Azure Linux:3 / python-urllib3

Package

Name
python-urllib3
Purl
pkg:rpm/azure-linux/python-urllib3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.7-5

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86862.json"