CVE-2018-18074: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 7.4% chance of exploitation in the next 30 days.

The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Opensuse Leap: version 15.1 only
  • Python Requests: before 2.20.0 (fixed in 2.20.0)
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2018-10-09. Last modified 2026-06-17.