CVE-2023-43804 MEDIUM

CVE-2023-43804: `Cookie` HTTP header isn't stripped on cross-origin redirects

Vendor Urllib3
Product urllib3
Weakness CWE-200 · Info exposure
Published October 4, 2023
Last update November 3, 2025

CVSS base score

5.9/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.

Key dates

02Disclosure timeline

October 4, 2023 CVE published
November 3, 2025 Record updated