By vendor

Pylonsproject vulnerabilities

Known CVEs affecting Pylonsproject products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-44889MEDIUM 6.1

    WebOb, a widely-used Python library for HTTP request and response handling, contains an open redirect vulnerability in how it processes redirect locations. An attacker can craft a malicious redirect URL containing whitespace characters (tabs, carriage returns, newlines) that bypass existing protections, causing users to be sent to an attacker-controlled website instead of the legitimate destination. The vulnerability affects versions before 1.8.10 and relies on the user clicking a link or visiting a page that triggers the vulnerable redirect.