CVE-2026-55403: Koxudaxi Datamodel-Code-Generator

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_generator/http.py get_body reuses Authorization, Cookie, and Proxy-Authorization headers when following cross-origin redirects while fetching remote schemas, allowing credentials scoped to one schema host to be leaked to another redirect target. This issue is fixed in version 0.63.0.

Affected products

  • Koxudaxi Datamodel-Code-Generator: before 0.63.0 (fixed in 0.63.0)

Published 2026-07-28. Last modified 2026-07-30.