In python-requests before 2.6.0, a cookie without a host value set would use the hostname for the redirected URL exposing requests users to session fixation attacks and potentially cookie stealing (CVE-2015-2296).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2015-0120.json"