CVE-2026-55403: Koxudaxi Datamodel-Code-Generator
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_generator/http.py get_body reuses Authorization, Cookie, and Proxy-Authorization headers when following cross-origin redirects while fetching remote schemas, allowing credentials scoped to one schema host to be leaked to another redirect target. This issue is fixed in version 0.63.0.
Affected products
- Koxudaxi Datamodel-Code-Generator: before 0.63.0 (fixed in 0.63.0)
Published 2026-07-28. Last modified 2026-07-30.