By vendor
Pylonsproject vulnerabilities
Known CVEs affecting Pylonsproject products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-44889MEDIUM 6.1
WebOb, a widely-used Python library for HTTP request and response handling, contains an open redirect vulnerability in how it processes redirect locations. An attacker can craft a malicious redirect URL containing whitespace characters (tabs, carriage returns, newlines) that bypass existing protections, causing users to be sent to an attacker-controlled website instead of the legitimate destination. The vulnerability affects versions before 1.8.10 and relies on the user clicking a link or visiting a page that triggers the vulnerable redirect.