Skip to content

CVE-2026-44889

is CVE-2026-44889real, exploitable, or a false positive? Here's the community verdict.

Medium · CVSS 6.1EPSS 0.2%CWE-601

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips ASCII tab, carriage return, and newline characters before parsing, so a redirect target containing such characters can be reinterpreted as a protocol-relative URL whose authority is an attacker-controlled host. This bypasses the CVE-2024-42353 fix that escaped a leading double slash, allowing an attacker who influences the redirect location to send users to an arbitrary external site instead of the intended one. This vulnerability is fixed in 1.8.10.

Published

Embed this verdict
TruePositive verdict for CVE-2026-44889
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2026-44889/badge.svg)](https://www.truepositive.app/cve/CVE-2026-44889)
HTML
<a href="https://www.truepositive.app/cve/CVE-2026-44889"><img src="https://www.truepositive.app/cve/CVE-2026-44889/badge.svg" alt="TruePositive verdict for CVE-2026-44889"></a>

Live badge that updates automatically as the community verdict changes.

Community ground truth

In your experience, is this finding real and exploitable?

0 verdicts
Not a real issue

No account needed. Anonymous verdicts post as an unverified signal. Log in to make yours verified and earn reputation.

Field notes & remediation

Verdicts are the quick signal. Notes are the evidence and fixes behind them.

No notes yet. Be the first to share what you saw, or a fix that worked.

    Add a field note or remediationoptional
    Note type

    What are you adding?

    Markdown supported · minimum 20 characters.

    Same weakness: CWE-601.