THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hq3h-g68c-hp78 (high) — urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage

[GHSA] GHSA-hq3h-g68c-hp78 (high) — urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage

highgithub_advisoriesPublished 2026-08-25

GHSA-hq3h-g68c-hp78 Severity: high CVE: CVE-2026-55553

urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage

## Summary

urllib supports redirect-following through `followRedirect`, which is expected behavior for an HTTP client. The issue is that, when following a redirect to a **different origin**, urllib preserves the caller-suppli

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hq3h-g68c-hp78