{"id":"AZL-86862","summary":"CVE-2026-44431 affecting package python-urllib3 for versions less than 2.0.7-5","details":"urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.","modified":"2026-09-16T06:39:01Z","published":"2026-05-13T16:16:57Z","upstream":["CVE-2026-44431"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44431"}],"affected":[{"package":{"name":"python-urllib3","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/python-urllib3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.7-5"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-86862.json"}}],"schema_version":"1.9.0"}