CVE-2018-18074: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 7.4% chance of exploitation in the next 30 days.
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
- Opensuse Leap: version 15.1 only
- Python Requests: before 2.20.0 (fixed in 2.20.0)
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
Published 2018-10-09. Last modified 2026-06-17.