Vulnerability record · CVE-2018-25091 · published 15 October 2023
CVE-2018-25091: Python urllib3 open redirect vulnerability
Python · Urllib3
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
Description
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc | Patch |
| https://github.com/urllib3/urllib3/compare/1.24.1...1.24.2 | Patch |
| https://github.com/urllib3/urllib3/issues/1510 | Issue TrackingPatchVendor Advisory |
| https://github.com/urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc | Patch |
| https://github.com/urllib3/urllib3/compare/1.24.1...1.24.2 | Patch |
| https://github.com/urllib3/urllib3/issues/1510 | Issue TrackingPatchVendor Advisory |
Track CVE-2018-25091 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-25091), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.