CVE-2023-43804

Aliases:GHSA-v845-jxx5-vc9fPYSEC-2023-192ALPINE-CVE-2023-43804RHSA-2024:0187RHSA-2024:2159RHSA-2024:2986DEBIAN-CVE-2023-43804CGA-28jr-w7hw-88mhCGA-3qfm-x3cp-698mCGA-6gp9-wwgc-mr68CGA-9m4f-jh37-fq84CGA-g9mq-h873-4vm3CGA-jcx9-mj76-7v92CGA-phpj-74wh-x9cmCGA-pwqv-6c73-2977CGA-2pr2-6gqp-gxrcCGA-37rg-2p6f-96rvCGA-4qqg-933j-r6grCGA-4qrf-xx73-27j8CGA-c465-wpp9-fp88CGA-fr35-6p94-2mxfCGA-rv7g-4vcj-94g9CGA-v773-c6mq-2c57CGA-vxp9-8g52-cf96CGA-w8fx-fwfr-92w3CGA-xg4r-x3fc-57q6CGA-xrpq-pv8v-m7gv
Modified
Published: 04 Oct 2023, 16:01
Last modified:03 Nov 2025, 21:49

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.1 HIGH
v3.1 (nvd)
EPSS Score
1.21% LOW
1% probability +0.34%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 Oct 2023, 16:01
Published
Vulnerability first disclosed
03 Nov 2025, 21:49
Last Modified
Vulnerability information updated

Description

urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.

CVSS Metrics

  • v4.0HIGHScore: 7.4CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 1.21% Percentile: 67%

Techniques & Countermeasures

  • CWE-200Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Affected Systems

  • alpinepy3-urllib3

    < 1.26.17-r0 | < 1.26.17-r0 | < 1.26.17-r0 | < 1.26.17-r0 | < 1.26.17-r0 | < 1.26.17-r0 | < 1.26.17-r0 | < 1.26.17-r0 | < 1.26.17-r0 | < 1.26.17-r0

  • chainguarddask-gateway

    < 2023.9.0-r1

  • chainguardgraalvm-24-graalpy-venv

    all

  • chainguardk8s-sidecar

    < 1.25.1-r2

  • chainguardkube-downscaler

    < 23.2.0-r6

  • chainguardkubeflow-jupyter-web-app

    < 1.7.0-r5

  • chainguardkubeflow-volumes-web-app

    < 1.7.0-r6

  • chainguardpy3-urllib3

    < 2.0.6-r0

  • chainguardpy3.13-scanner-test-libraries

    < 0.0.1-r2

  • chainguardpy3.13-scanner-test-scanner-test-python-vulnerability-fixed

    all

  • chainguardpy3.13-scanner-test-scanner-test-python-vulnerability-unfixed

    all

  • wolfidask-gateway

    < 2023.9.0-r1

  • wolfik8s-sidecar

    < 1.25.1-r2

  • wolfikube-downscaler

    < 23.2.0-r6

  • wolfikubeflow-jupyter-web-app

    < 1.7.0-r5

  • wolfikubeflow-volumes-web-app

    < 1.7.0-r6

  • wolfipy3-urllib3

    < 2.0.6-r0

  • debianpython-urllib3

    < 1.26.5-1~exp1+deb11u1 | < 1.26.12-1+deb12u1 | < 1.26.17-1 | < 1.26.17-1

  • debiandebian_linux

    10.0

  • fedoraprojectfedora

    37 | 38 | 39

  • PyPIurllib3

    < 01220354d389cd05474713f8c982d05c9b17aafb | ≥ 2.0.0, < 2.0.6 | < 1.26.17

  • pythonurllib3

    < 1.26.17 | ≥ 2.0.0, < 2.0.6

  • redhatpython-urllib3

    < 0:1.25.10-5.el8ost

  • redhatpython3-urllib3

    < 0:1.25.10-5.el8ost

  • redhatpython3.11-urllib3

    < 0:1.26.12-2.el9 | < 0:1.26.12-2.el8

  • urllib3urllib3

    ≥ 2.0.0, < 2.0.6 | < 1.26.17

References (32)