Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-25091

20
FAUCET Score

CVE-2018-25091 is a medium-severity vulnerability affecting urllib3 before version 1.24.2, where the authorization HTTP header is not removed during cross-origin redirects, potentially exposing credentials to unintended hosts or in cleartext. This client-side vulnerability requires user interaction and can lead to low impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this issue.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.24.2CPE matchmatch criteria
cpe:2.3:a:python:urllib3:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.51%
Probability of exploitation in next 30 days
EPSS Percentile
40.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0051 is in the 43rd percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

denopatch availablevia llm_extracted
View patch
github_advisorypatch availablevia nvd_reference
View patch
keraspatch availablevia llm_extracted
View patch
pippatch availablevia ghsa
Product: urllib3Fixed in: 1.24.2
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: container-tools:rhel8-8100020240227110532.82888897
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift Data Science (RHODS)Fixed in: rhods/odh-ml-pipelines-cache-rhel8
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: python-urllib3
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/baremetal-hardware-event-proxy-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Storage 3Fixed in: graphite-web

Vendor Advisories (5)

denollm-deno-650ac71876afb4f8CRITICAL

HP ThinPro 8.1 SP 2 Security Updates

Apr 12, 2024
kerasllm-keras-d13bbd8768a57997CRITICAL

HP ThinPro 8.1 SP 2 Security Updates

Apr 12, 2024
pipGHSA-gwvm-45gx-3cf8medium

Authorization Header forwarded on redirect

Oct 15, 2023
redhatCVE-2018-25091Moderate

urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect

Oct 15, 2023
microsoft2023-Oct/CVE-2018-25091

urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).

Oct 10, 2023

References

github.com / urllib3/urllib3/commit/adb358f8e06865406d1f05e581a16cbea2136fbc
Patch
github.com / urllib3/urllib3/compare/1.24.1...1.24.2
Patch
github.com / urllib3/urllib3/issues/1510
Issue TrackingPatchVendor Advisory