CVE-2018-20060: Fedoraproject Fedora

Critical severity, CVSS 9.8. EPSS: 4.5% chance of exploitation in the next 30 days.

urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.

Affected products

  • Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
  • Python URLLIB3: before 1.23 (fixed in 1.23)

Published 2018-12-11. Last modified 2026-06-17.