USN-8811-1: urllib3 vulnerability
AI summary · grok-4.7
Ubuntu fixed an urllib3 flaw that can leak sensitive HTTP headers on cross-origin redirects.
Ubuntu Security Notice USN-8811-1 says urllib3 did not correctly strip sensitive HTTP headers during cross-origin redirects. An attacker could possibly use that behavior to leak sensitive information. The notice does not report observed exploitation.
- urllib3 could retain sensitive headers across cross-origin redirects.
- Ubuntu shipped a fix in USN-8811-1.
- The notice does not report active exploitation.
Full article
It was discovered that urllib3 did not correctly strip sensitive HTTP headers during cross-origin redirects. An attacker could possibly use this issue to leak sensitive information.
This source does not provide full text. Read it at ubuntu.com.