CVE-2026-44431
Red Hat Security Advisory: RHOAI 3.3.5 - Red Hat OpenShift AI
Beschreibung
Urllib3 ist eine HTTP-Client-Bibliothek für Python. Von Version 1.23 bis vor 2.7.0 folgen Querdomänen-Umleitungen über die niedrigstufige API mittels ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) und leiten diese sensiblen Header weiter. Dieses Sicherheitsproblem wurde in Version 2.7.0 behoben.
Metriken
Weakness-Klassen (CWE)
CWE-200Class
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
cwe.mitre.org →
Betroffene Betriebssysteme
linux
debian / debian_linux11.0
linux
redhat / enterprise_linux_ai3.0
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
aiohttp
aiohttp3.13.3
aiohttp
aiohttp3.14.0
bitnami
mlflow
cryptography.io
cryptography45.0.0 – 46.0.7
danthedeckie
simpleeval1.0.5
encode
starlette0.8.3 – 1.0.1
golang
crypto0.52.0
golang
go1.25.0 – 1.25.6
golang
go1.24.12
grpc
grpc1.79.3
huggingface
transformers
IBM
Concert< 3.0.0
gefixt in 3.0.0
IBM
QRadar SIEM<7.5.0 UP15 IF06
keras
keras
langchain
langchain_core1.2.22
nltk
nltk3.9.3
protobufjs_project
protobufjs7.5.5
protobufjs_project
protobufjs
pyasn1
pyasn10.6.2
pyasn1
pyasn10.6.3
pyjwt_project
pyjwt2.12.0
pyjwt_project
pyjwt2.13.0
pypa
pip26.1.2
pypi
multipart0.1
Quellen & Referenzen
- https://github.com/protobufjs/protobuf.js/security/advisories/GHSA-xq3m-2v4x-88ggweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-41242advisory
- https://github.com/protobufjs/protobuf.js/commit/535df444ac060243722ac5d672db205e5c531d75web
- https://github.com/protobufjs/protobuf.js/commit/ff7b2afef8754837cc6dc64c864cd111ab477956web
- https://github.com/protobufjs/protobuf.jspackage
- https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v7.5.5web
- https://github.com/protobufjs/protobuf.js/releases/tag/protobufjs-v8.0.1web
- https://access.redhat.com/security/cve/CVE-2026-41242vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2459442issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41242.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:21338vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:26234vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:24977vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:37275vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:62260vendor-advisoryx_refsource_REDHAT
- https://github.com/remix-run/react-router/security/advisories/GHSA-8646-j5j9-6r62web
- https://nvd.nist.gov/vuln/detail/CVE-2026-33245advisory
- https://github.com/remix-run/react-routerpackage
- https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wxevidence
- https://access.redhat.com/security/cve/CVE-2026-48526vdb-entryx_refsource_REDHAT
Verknüpfte CVEs
- CVE-2026-8643
Pip würde `console_scripts` und `gui_scripts` als Pfade statt Dateinamen behandeln, ohne den aufgelösten absoluten Pfad zum Installations…
highCVSSv3 8.0 - CVE-2026-5241
Eine Schwachstelle im Modell-Ladepfad von LightGlue in der Version 5.2.0 des huggingface/transformers-Pakets ermöglicht es einem Angreife…
criticalCVSSv3 9.6 - CVE-2026-48710Aktiv ausgenutzt
Starlette ist ein leichtgewichtiges ASGI-Framework/Toolkit.
criticalCVSSv3 6.5 - CVE-2026-48526
PyJWT ist eine Implementierung von JSON Web Token in Python.
highCVSSv3 7.4 - CVE-2026-46595
Früher wurde durch CVE-2024-45337 ein Umgehen der Autorisierung bei fehlerhaften SSH-Serverkonfigurationen behoben; wenn eine andere Art…
criticalCVSSv3 10.0 - CVE-2026-44432
urllib3 ist eine HTTP-Client-Bibliothek für Python.
highCVSSv3 7.5 - CVE-2026-42561
Python-Multipart ist ein Streaming-Multipart-Parser für Python.
highCVSSv3 7.5 - CVE-2026-41242
`protobufjs` kompiliert Protobuf-Definitionen in JavaScript (JS)-Funktionen.
criticalCVSSv3 9.8 - CVE-2026-40192
Pillow ist eine Python-Bildverarbeitungsbibliothek.
highCVSSv3 7.5 - CVE-2026-39892
Die Kryptographie ist ein Paket, das kryptografische Primitive und Rezepte für Python-Entwickler bereitstellt.
criticalCVSSv3 9.8 - CVE-2026-39830
Ein böswilliger SSH-Peer könnte unbeauftragte globale Antwortnachrichten senden, um einen internen Puffer zu füllen und den Lese-Schleife…
criticalCVSSv3 9.1 - CVE-2026-35536
Ein Fehler wurde in Tornado gefunden.
highCVSSv3 7.2 - CVE-2026-34993
Ein Fehler wurde im AIOHTTP gefunden, einem asynchronen HTTP-Client/Server-Framework für asyncio und Python.
highCVSSv3 7.3 - CVE-2026-34070
LangChain ist ein Framework zum Aufbau von Agenten und LLM-gestützten Anwendungen.
highCVSSv3 7.5 - CVE-2026-33699
pypdf ist eine kostenlose und quelloffene reine Python-PDF-Bibliothek.
medium - CVE-2026-33245
Ein Fehler wurde bei React Router gefunden.
highCVSSv3 8.0 - CVE-2026-33236
NLTK (Natural Language Toolkit) ist ein Paket von Open-Source-Python-Modulen, Datensätzen und Tutorials zur Unterstützung von Forschung u…
highCVSSv3 8.1 - CVE-2026-33231
NLTK (Natural Language Toolkit) ist ein Paket von Open-Source-Python-Modulen, Datensätzen und Tutorials zur Unterstützung von Forschung u…
highCVSSv3 7.5 - CVE-2026-33186
gRPC-Go ist die Go-Sprachimplementierung von gRPC.
criticalCVSSv3 9.1 - CVE-2026-32640
SimpleEval ist eine Bibliothek zum Hinzufügen auswertbarer Ausdrücke zu Python-Projekten.
criticalCVSSv3 9.8 - CVE-2026-32597
Es wurde ein fehlender Überprüfungsschritt in PyJWT entdeckt.
highCVSSv3 7.5 - CVE-2026-31958
Tornado ist ein Python-Webframework und eine asynchrone Netzwerk-Bibliothek.
high - CVE-2026-30922
pyasn1 ist eine generische ASN.1-Bibliothek für Python.
highCVSSv3 7.5 - CVE-2026-28684
Ein Fehler wurde in python-dotenv gefunden.
mediumCVSSv3 6.6
7 weitere CVEs anzeigen
- CVE-2026-28356
Multipart ist ein schneller Parser für `multipart/form-data` für Python.
highCVSSv3 7.5 - CVE-2026-27893
vLLM ist ein Inferenz- und Bereitstellungsmotor für große Sprachmodelle (LLMs).
highCVSSv3 8.8 - CVE-2026-2614
Eine Schwachstelle im Handler `_create_model_version()` von `mlflow/server/handlers.py` in mlflow/mlflow-Versionen 3.9.0 und früher ermög…
highCVSSv3 7.5 - CVE-2026-23490
pyasn1 ist eine generische ASN.1-Bibliothek für Python.
highCVSSv3 7.5 - CVE-2026-1462
Eine Schwachstelle im `TFSMLayer`-Klasse des `keras`-Pakets, Version 3.13.0, ermöglicht es Angreifern, kontrollierte TensorFlow SavedMode…
highCVSSv3 8.8 - CVE-2025-69223
AIOHTTP ist ein asynchroner HTTP-Client/Server-Framework für asyncio und Python.
highCVSSv3 7.5 - CVE-2025-61726
Das Paket `net/url` setzt keine Begrenzung für die Anzahl der Abfrageparameter in einer Abfrage fest.
highCVSSv3 7.5