REDHAT-BUG-2431366: Medium severity Python urllib.request.DataHandler vulnerability
Published Jan 20, 2026
·Updated
User-controlled data URLs parsed by urllib.request.DataHandler allow injecting headers through newlines in the data URL mediatype.
Affected Software
1 affected component
Python urllib.request.DataHandler
Event History
Jan 20, 2026
Data Sourced
via Red Hat·10:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2431366?
The severity of REDHAT-BUG-2431366 is considered high due to the potential for header injection through user-controlled data URLs.
2
How do I fix REDHAT-BUG-2431366?
To fix REDHAT-BUG-2431366, ensure that data URLs are sanitized to prevent header injection.
3
What software is affected by REDHAT-BUG-2431366?
REDHAT-BUG-2431366 affects the Python urllib.request.DataHandler module.
4
Is REDHAT-BUG-2431366 an exploitable vulnerability?
Yes, REDHAT-BUG-2431366 can be exploited by attackers to inject malicious headers into requests.
5
What should I do if I am using an affected version of urllib.request.DataHandler related to REDHAT-BUG-2431366?
If using an affected version, you should apply the necessary patches or upgrades recommended by Red Hat to mitigate the vulnerability.