THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6hx8-3wjj-gr8g (medium) — WebOb: Open redirect in Location header normalization via leading C0 control / space characters

[GHSA] GHSA-6hx8-3wjj-gr8g (medium) — WebOb: Open redirect in Location header normalization via leading C0 control / space characters

highgithub_advisoriesPublished 2026-08-27

GHSA-6hx8-3wjj-gr8g Severity: medium CVE: CVE-2026-54770

WebOb: Open redirect in Location header normalization via leading C0 control / space characters

## Summary

This is a third follow-up to **CVE-2024-42353 / GHSA-mg3v-6m49-jhp3** and **CVE-2026-44889 / GHSA-fh3h-vg37-cc95**.

WebOb makes the `Location` header absolute when it serves a redirect. To stop a relative or protocol-relative target

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6hx8-3wjj-gr8g