CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-55403

lowCVSS 3.7covered by 2 sourcesfirst seen 2026-07-28
Summary When datamodel-code-generator fetches a remote schema and follows an HTTP redirect, it re-sends the original request headers, including any Authorization header, to the redirect target even when the redirect changes origin (host/port/scheme). Credentials that an operator scoped to a trusted schema host are therefore forwarded to an attacker-controlled or otherwise different host, leaking them. Details In src/datamodel_code_generator/http.py, get_body() follows redirects manually and re-issues each hop with the same headers argument, with no check that the origin is unchanged: for redirect_count in range(MAX_HTTP_REDIRECTS + 1): _validate_url_for_fetch(current_url, allow_private_network=allow_private_network) response = httpx.get(current_url, headers=headers, follow_redirects=False, ...) # same headers every hop if (redirect_url := _get_redirect_url(httpx, current_url, response)) is None: break current_url = redirect_url Browsers and HTTP clients such as requests/httpx strip Authorization when a redirect crosses origin; here it is preserved unconditionally. Headers are operator-supplied via --http-headers (and credentials can also arrive through --url userinfo), so a redirect from the trusted host to any other host discloses them. PoC Self-contained reproducer: https://gist.github.com/thegr1ffyn/ade3035d7f2be95e16f11698259cdbc2 Host A (the trusted schema host) 302-redirects to host B (a different origin) which records received headers; the request carries an auth token scoped to A. (The PoC uses loopback servers; allow_private_network=True is only to avoid the separate SSRF guard blocking loopback and has no bearing on the leak.) Impact Exposure of sensitive information to an unauthorized actor (CWE-200). Affects operators who pass authentication headers/credentials to fetch a remote schema (--http-headers, --url with userinfo) when the configured host issues a redirect to a different origin — e.g. a compromised or open-redirect-prone schema host, o

⚡ Watch CVE-2026-55403

Get an email if CVE-2026-55403 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-55403

CVE.org record

Embed the live status

CVE-2026-55403 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-55403 status](https://www.csirts.com/badge/CVE-2026-55403)](https://www.csirts.com/cve/CVE-2026-55403)