VYPR
Medium severity6.1NVD Advisory· Published Aug 14, 2024· Updated Jun 17, 2026

CVE-2024-42353

CVE-2024-42353

Description

WebOb provides objects for HTTP requests and responses. When WebOb normalizes the HTTP Location header to include the request hostname, it does so by parsing the URL that the user is to be redirected to with Python's urlparse, and joining it to the base URL. urlparse however treats a // at the start of a string as a URI without a scheme, and then treats the next part as the hostname. urljoin will then use that hostname from the second part as the hostname replacing the original one from the request. This vulnerability is patched in WebOb version 1.8.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
webobPyPI
< 1.8.81.8.8

Affected products

10

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.