{"id":"CVE-2023-43804","aliases":["GHSA-v845-jxx5-vc9f","PYSEC-2023-192"],"title":"`Cookie` HTTP header isn't stripped on cross-origin redirects","summary":"`Cookie` HTTP header isn't stripped on cross-origin redirects","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","vendor":"urllib3","product":"urllib3","ecosystem":"pip","affected":["urllib3 >= 2.0.0, < 2.0.6","urllib3 < 1.26.17"],"patched":["urllib3 2.0.6","urllib3 1.26.17"],"published":"2023-10-02","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:24.753610811Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-v845-jxx5-vc9f","references":[{"url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-v845-jxx5-vc9f"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-43804"},{"url":"https://github.com/urllib3/urllib3/commit/01220354d389cd05474713f8c982d05c9b17aafb"},{"url":"https://github.com/urllib3/urllib3/commit/644124ecd0b6e417c527191f866daa05a5a2056d"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-192.yaml"},{"url":"https://github.com/urllib3/urllib3"},{"url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00012.html"},{"url":"https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I3PR7C6RJ6JUBQKIJ644DMIJSUP36VDY"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAGZXYJ7H2G3SB47M453VQVNAWKAEJJ"},{"url":"https://security.netapp.com/advisory/ntap-20241213-0007"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2023-43804-urllib3-vulnerability-3"}],"tags":["osv","pip","exploit-available"],"epss":0.01207,"epssPercentile":0.66543,"ingestedAt":"2026-09-12T03:13:01.729Z","exploits":{"github":1,"githubRepos":["https://github.com/deepanshu-khurana/CVE-2023-43804"],"checkedAt":"2026-09-21T15:25:56.379Z"},"exploitAvailable":true,"slug":"CVE-2023-43804","body":"## Overview\n\nurllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly.\n\nUsers **must** handle redirects themselves instead of relying on urllib3's automatic redirects to achieve safe processing of the `Cookie` header, thus we decided to strip the header by default in order to further protect users who aren't using the correct approach.\n\n## Affected usages\n\nWe believe the number of usages affected by this advisory is low. It requires all of the following to be true to be exploited:\n\n* Using an affected version of urllib3 (patched in v1.26.17 and v2.0.6)\n* Using the `Cookie` header on requests, which is mostly typical for impersonating a browser.\n* Not disabling HTTP redirects\n* Either not using HTTPS or for the origin server to redirect to a malicious origin.\n\n## Remediation\n\n* Upgrading to at least urllib3 v1.26.17 or v2.0.6\n* Disabling HTTP redirects using `redirects=False` when sending requests.\n* Not using the `Cookie` header.\n\n## Affected packages\n\n- `urllib3 >= 2.0.0, < 2.0.6`\n- `urllib3 < 1.26.17`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `urllib3 2.0.6`\n- `urllib3 1.26.17`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":32.5,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":208437,"id":"CVE-2023-43804","ts":1790004990425,"field":"exploit_available","old":"false","new":"true"}]}