---
id: CVE-2023-43804
aliases:
  - GHSA-v845-jxx5-vc9f
  - PYSEC-2023-192
title: '`Cookie` HTTP header isn''t stripped on cross-origin redirects'
summary: '`Cookie` HTTP header isn''t stripped on cross-origin redirects'
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'
vendor: urllib3
product: urllib3
ecosystem: pip
affected:
  - 'urllib3 >= 2.0.0, < 2.0.6'
  - urllib3 < 1.26.17
patched:
  - urllib3 2.0.6
  - urllib3 1.26.17
published: '2023-10-02'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:49:24.753610811Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-v845-jxx5-vc9f'
references:
  - url: 'https://github.com/urllib3/urllib3/security/advisories/GHSA-v845-jxx5-vc9f'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-43804'
  - url: >-
      https://github.com/urllib3/urllib3/commit/01220354d389cd05474713f8c982d05c9b17aafb
  - url: >-
      https://github.com/urllib3/urllib3/commit/644124ecd0b6e417c527191f866daa05a5a2056d
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/urllib3/PYSEC-2023-192.yaml
  - url: 'https://github.com/urllib3/urllib3'
  - url: 'https://lists.debian.org/debian-lts-announce/2023/10/msg00012.html'
  - url: 'https://lists.debian.org/debian-lts-announce/2024/12/msg00020.html'
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5F5CUBAN5XMEBVBZPHFITBLMJV5FIJJ5
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I3PR7C6RJ6JUBQKIJ644DMIJSUP36VDY
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NDAGZXYJ7H2G3SB47M453VQVNAWKAEJJ
  - url: 'https://security.netapp.com/advisory/ntap-20241213-0007'
  - url: >-
      https://www.vicarius.io/vsociety/posts/cve-2023-43804-urllib3-vulnerability-3
tags:
  - osv
  - pip
  - exploit-available
epss: 0.01207
epssPercentile: 0.67008
ingestedAt: '2026-09-12T03:13:01.729Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/deepanshu-khurana/CVE-2023-43804'
  checkedAt: '2026-09-25T08:20:41.912Z'
exploitAvailable: true
---

## Overview

urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly.

Users **must** handle redirects themselves instead of relying on urllib3's automatic redirects to achieve safe processing of the `Cookie` header, thus we decided to strip the header by default in order to further protect users who aren't using the correct approach.

## Affected usages

We believe the number of usages affected by this advisory is low. It requires all of the following to be true to be exploited:

* Using an affected version of urllib3 (patched in v1.26.17 and v2.0.6)
* Using the `Cookie` header on requests, which is mostly typical for impersonating a browser.
* Not disabling HTTP redirects
* Either not using HTTPS or for the origin server to redirect to a malicious origin.

## Remediation

* Upgrading to at least urllib3 v1.26.17 or v2.0.6
* Disabling HTTP redirects using `redirects=False` when sending requests.
* Not using the `Cookie` header.

## Affected packages

- `urllib3 >= 2.0.0, < 2.0.6`
- `urllib3 < 1.26.17`

## Remediation

Upgrade to a patched release:

- `urllib3 2.0.6`
- `urllib3 1.26.17`
