------------------------------------------------------------------------- Debian LTS Advisory DLA-4651-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Guilhem Moulin June 26, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : python-urllib3 Version : 1.26.5-1~exp1+deb11u4 1.26.12-1+deb12u4 CVE ID : CVE-2026-44431 Debian Bug : 1136653 It was discovered that python-urllib3, an HTTP library with thread-safe connection pooling for Python, did not strip out sensitive headers (such as `Authorization` or `Cookie`) during cross-origin redirects followed from the low-level API, which could lead to information disclosure or authorization bypass. For Debian 11 bullseye, this problem has been fixed in version 1.26.5-1~exp1+deb11u4. For Debian 12 bookworm, this problem has been fixed in version 1.26.12-1+deb12u4. We recommend that you upgrade your python-urllib3 packages. For the detailed security status of python-urllib3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python-urllib3 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment:
signature.asc
Description: PGP signature