CVE-2023-43804 is an information-disclosure vulnerability in the Python urllib3 HTTP client library. When an application explicitly supplies a Cookie HTTP header and urllib3 automatically follows an HTTP redirect to a different origin, urllib3 can forward the user-supplied Cookie header to that redirected origin. urllib3 does not provide cookie management helpers, leaving header handling to the calling application. The issue is fixed in urllib3 1.26.17 and later releases in the 1.x branch, and in fixed 2.x releases.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a containerized reproduction lab for CVE-2023-43804, an urllib3 flaw in which sensitive headers such as Cookie may be retained when a client follows a cross-origin redirect. The repository contains an exploit client (exploit.py), a redirecting Flask target (target_server/app.py), an attacker-controlled Flask collection server (attacker_server/app.py), and Docker Compose/Dockerfiles that create an isolated three-container environment. exploit.py uses urllib3.PoolManager with an explicit HTTPHeaderDict containing a hardcoded session cookie, requests http://target_app:5000/redirect, and follows redirects. The target responds with a 302 to http://attacker_app:5001/steal; the attacker endpoint records request source information and the received Cookie header, then returns JSON indicating whether exfiltration occurred. The empty detect.py and setup.sh do not implement detection or setup functionality. The README documents testing vulnerable urllib3 1.26.16 and verifying remediation with 1.26.17; no dependency version is pinned in client_environment/requirements.txt.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Important-severity vulnerability tracked as CVE-2023-43804, with network attack vector, low attack complexity, required low privileges, and high confidentiality and integrity impact according to the supplied CVSS v3 assessment.
Addressed in updated multicluster engine for Kubernetes images; flaw details are not supplied.
Unknown
Unknown.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.