CVE-2024-37891Medium· 4.4▾ Sunliturllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.2 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
1.1%
Last analysed / modified upstream
When using urllib3's proxy support with ProxyManager, the Proxy-Authorization header is only sent to the configured proxy, as expected.
However, when sending HTTP requests without using urllib3's proxy support, it's possible to accidentally configure the Proxy-Authorization header even though it won't have any effect as the request is not using a forwarding proxy or a tunneling proxy. In those cases, urllib3 doesn't treat the Proxy-Authorization HTTP header as one carrying authentication material and thus doesn't strip the header on cross-origin redirects.
Because this is a highly unlikely scenario, we believe the severity of this vulnerability is low for almost all users. Out of an abundance of caution urllib3 will automatically strip the Proxy-Authorization header during cross-origin redirects to avoid the small chance that users are doing this on accident.
Users should use urllib3's proxy support or disable automatic redirects to achieve safe processing of the Proxy-Authorization header, but we still decided to strip the header by default in order to further protect users who aren't using the correct approach.
We believe the number of usages affected by this advisory is low. It requires all of the following to be true to be exploited:
Proxy-Authorization header without using urllib3's built-in proxy support.Proxy-Authorization header with urllib3's ProxyManager.redirects=False when sending requests.Proxy-Authorization header.urllib3 < 1.26.19urllib3 >= 2.0.0, < 2.2.2Upgrade to a patched release:
urllib3 1.26.19urllib3 2.2.2Connected by shared product, vendor, weakness, or advisory.
CVE-2023-43804Medium· 5.9`Cookie` HTTP header isn't stripped on cross-origin redirects
CVE-2023-45803Medium· 4.2urllib3's request body not stripped after redirect from 303 status changes request method to GET
CVE-2021-33503High· 7.5Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
CVE-2025-50181Medium· 5.3urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
CVE-2025-66418Highurllib3 allows an unbounded number of links in the decompression chain
CVE-2021-28363Medium· 6.5Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection