6

CVE-2026-15806

`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching

The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.

Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.

Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerPython Software Foundation
≫
Produkt CPython
Default Statusunaffected
Version 0
Version < 3.10.22
Status affected
Version 3.11.0
Version < 3.11.17
Status affected
Version 3.12.0
Version < 3.12.15
Status affected
Version 3.13.0
Version < 3.13.16
Status affected
Version 3.14.0
Version < 3.14.8
Status affected
Version 3.15.0a1
Version < 3.15.0rc2
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.305
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cna@python.org 6 0 0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://github.com/python/cpython/issues/155694
https://github.com/python/cpython/pull/155696
https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/
https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8
https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce
https://github.com/python/cpython/commit/a7bb524fef61f77ede01f660ffbd591e1d5837ce
http://www.openwall.com/lists/oss-security/2026/08/18/3
https://github.com/python/cpython/commit/641be42bb07921ba0f8bffe228b1dc706b092ef6
https://github.com/python/cpython/commit/851cf9a7142ecbdd39f831055533f58284ad2bcc
https://github.com/python/cpython/commit/95355ee3a8e1d3c3d4858d1973aa42a9b91a2801
https://github.com/python/cpython/commit/dac88d8615078c55f1304ea4c7a2d822700d4e5a