Credential Matching Issue in Python’s urllib.request Module
CVE-2026-15806
What is CVE-2026-15806?
The urllib.request module in Python contains a vulnerability whereby the HTTPPasswordMgr class and its subclasses ignore the URL scheme when matching stored credentials. This allows attackers to exploit the mismatch between http and https requests, potentially capturing credentials in cleartext through redirection or downgrading attacks. To address this issue, credential matching is now scoped by URL scheme, ensuring that credentials registered for a specific URI are only sent for requests with the same protocol. Users should avoid making plain HTTP requests for URLs with associated credentials and consider upgrading to the latest version for enhanced security.
Affected Version(s)
CPython 0 < 3.12.15
CPython 3.13.0 < 3.13.16
CPython 3.14.0 < 3.14.8
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
