THREAT OPS › Threat News › [GHSA] GHSA-6hx8-3wjj-gr8g (medium) — WebOb: Open redirect in Location header normalization via leading C0 control / space characters
[GHSA] GHSA-6hx8-3wjj-gr8g (medium) — WebOb: Open redirect in Location header normalization via leading C0 control / space characters
GHSA-6hx8-3wjj-gr8g Severity: medium CVE: CVE-2026-54770
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
## Summary
This is a third follow-up to **CVE-2024-42353 / GHSA-mg3v-6m49-jhp3** and **CVE-2026-44889 / GHSA-fh3h-vg37-cc95**.
WebOb makes the `Location` header absolute when it serves a redirect. To stop a relative or protocol-relative target
Indicators of compromise
- CVE-2026-54770cve
- CVE-2024-42353cve
- CVE-2026-44889cve
- https://yourhost/`url
- https://docs.python.org/3/library/urllib.parse.htmlurl
- https://attacker.example/pathurl
- pylons-project-security@googlegroups.comemail
Original source: https://github.com/advisories/GHSA-6hx8-3wjj-gr8g