{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/urllib--2.44.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-55553"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["urllib (\u003e= 3.0.0, \u003c= 4.9.0)","urllib (\u003c= 2.44.0)"],"_cs_severities":["medium"],"_cs_tags":["credential-theft","nodejs","supply-chain"],"_cs_type":"advisory","_cs_vendors":["node-modules"],"content_html":"\u003cp\u003eThe Node.js library \u003ccode\u003eurllib\u003c/code\u003e contains a vulnerability (CVE-2026-55553) where credential-bearing request headers are preserved verbatim when following HTTP redirects across different origins. While standard HTTP client behavior typically involves stripping sensitive authentication headers when a request is redirected to a different domain, \u003ccode\u003eurllib\u003c/code\u003e v4.9.0 and earlier versions (including the 2.x branch) fail to implement this security control. This allows an attacker who controls a redirect destination, or who can influence the \u003ccode\u003eLocation\u003c/code\u003e header of an initial request, to capture sensitive data such as \u003ccode\u003eAuthorization\u003c/code\u003e tokens, \u003ccode\u003eCookie\u003c/code\u003e session strings, and \u003ccode\u003eProxy-Authorization\u003c/code\u003e credentials. The vulnerability is triggered automatically when \u003ccode\u003efollowRedirect\u003c/code\u003e is set to \u003ccode\u003etrue\u003c/code\u003e, requiring no user interaction. This poses a significant risk to applications that handle sensitive API requests or user sessions through the affected library.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe impact of this vulnerability is the unauthorized exfiltration of sensitive credentials to attacker-controlled infrastructure. By redirecting a legitimate client request to a malicious origin, an attacker can capture authentication tokens, enabling them to potentially impersonate the client or access protected resources on the original target system. This vulnerability affects any Node.js environment utilizing \u003ccode\u003eurllib\u003c/code\u003e for external communication. Given the automated nature of redirect following, services that interface with dynamic or third-party content are at the highest risk of accidental credential exposure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003eurllib\u003c/code\u003e to a patched version once available that implements header sanitization for cross-origin requests.\u003c/li\u003e\n\u003cli\u003eImplement a wrapper or interceptor around \u003ccode\u003eurllib.request\u003c/code\u003e that checks the domain of the \u003ccode\u003eLocation\u003c/code\u003e header during a redirect and strips sensitive headers if the origin changes.\u003c/li\u003e\n\u003cli\u003eAudit applications using \u003ccode\u003eurllib\u003c/code\u003e to identify code paths where \u003ccode\u003efollowRedirect\u003c/code\u003e is enabled and potentially sensitive headers (Authorization, Cookie) are passed in the options object.\u003c/li\u003e\n\u003cli\u003eReview network egress logs for unexpected connections from your backend services to unknown or untrusted external domains.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T18:50:36Z","date_published":"2026-08-25T18:50:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-urllib-credential-leak/","summary":"The urllib library fails to sanitize sensitive headers during cross-origin redirects, leading to the automatic exposure of Authorization, Cookie, and Proxy-Authorization headers to unauthorized endpoints.","title":"urllib Cross-Origin Redirect Credential Leakage","url":"https://feed.craftedsignal.io/briefs/2026-08-urllib-credential-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Urllib (\u003c= 2.44.0)","version":"https://jsonfeed.org/version/1.1"}