<Vulnerability name="CVE-2026-55553">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-08-25T16:18:21</PublicDate>
    <Bugzilla id="2523609" url="https://bugzilla.redhat.com/show_bug.cgi?id=2523609" xml:lang="en:us">
urllib: urllib: Credential leakage via cross-origin redirects
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-201</CWE>
    <Details xml:lang="en:us" source="Mitre">
urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across origins. In src/HttpClient.ts, #requestInternal recursively calls this.#requestInternal(nextUrl.href, options, requestContext), causing options.headers and auth or digestAuth values to be reused when the redirect target has a different scheme, host, or port. Authorization, Cookie, Proxy-Authorization, x-api-key, x-auth-token, and x-access-token can therefore be sent to an attacker-controlled redirected origin, exposing credentials intended for the original origin and potentially allowing reuse against the original partner API or related services. No user interaction is required. This issue is fixed in versions 2.44.1 and 4.9.1.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in urllib. This HTTP client for Node.js can be exploited by a remote attacker due to improper handling of cross-origin redirects. When following redirects, urllib reuses sensitive request headers, such as Authorization and Cookie, across different origins. This can lead to the leakage of credentials to an attacker-controlled server, potentially allowing the attacker to reuse these credentials against the original service.
    </Details>
    <AffectedRelease cpe="cpe:/a:redhat:ansible_portal:2.1">
        <ProductName>Red Hat Ansible Automation Platform 2.1</ProductName>
        <ReleaseDate>2026-09-28T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:72712">RHSA-2026:72712</Advisory>
        <Package name="ansible-automation-platform/automation-portal">ansible-automation-platform/automation-portal:1790254963</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:ansible_portal:2.2">
        <ProductName>Red Hat Ansible Automation Platform 2.2</ProductName>
        <ReleaseDate>2026-09-28T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:72722">RHSA-2026:72722</Advisory>
        <Package name="ansible-automation-platform/automation-portal">ansible-automation-platform/automation-portal:1790256405</Package>
    </AffectedRelease>
    <AffectedRelease cpe="cpe:/a:redhat:rhdh:1.9::el9">
        <ProductName>Red Hat Developer Hub 1.9</ProductName>
        <ReleaseDate>2026-09-21T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:69248">RHSA-2026:69248</Advisory>
        <Package name="rhdh/rhdh-hub-rhel9">rhdh/rhdh-hub-rhel9:1789554285</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:rhdh:1">
        <ProductName>Red Hat Developer Hub</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhdh/red-hat-developer-hub-backstage-plugin-lightspeed-backend</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:rhdh:1">
        <ProductName>Red Hat Developer Hub</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:rhdh:1">
        <ProductName>Red Hat Developer Hub</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhdh/red-hat-developer-hub-backstage-plugin-orchestrator-backend-module-loki</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:rhdh:1">
        <ProductName>Red Hat Developer Hub</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhdh/red-hat-developer-hub-backstage-plugin-scaffolder-backend-module-orchestrator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:ansible_portal:2">
        <ProductName>Self-service automation portal 2</ProductName>
        <FixState>Affected</FixState>
        <PackageName>ansible-automation-platform/bootc-automation-portal-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-55553
https://nvd.nist.gov/vuln/detail/CVE-2026-55553
https://github.com/node-modules/urllib/commit/7c86c465883ebd3dea5109c87d7bbe3b00960a16
https://github.com/node-modules/urllib/commit/811a8d56e64e540bf6a19bf8b3737692f05d5c46
https://github.com/node-modules/urllib/pull/812
https://github.com/node-modules/urllib/pull/813
https://github.com/node-modules/urllib/releases/tag/v2.44.1
https://github.com/node-modules/urllib/releases/tag/v4.9.1
https://github.com/node-modules/urllib/security/advisories/GHSA-hq3h-g68c-hp78
    </References>
</Vulnerability>