CVE-2026-54770General

LOWCVSS 6.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An attacker-controlled value such as a space followed by a protocol-relative or absolute URL can therefore bypass SCHEME_RE and startswith("//") checks and be normalized to an off-host redirect. Request.relative_url() and webob.exc._HTTPMove subclasses, including HTTPFound, are also affected because they use the same unsafe URL joining behavior or bypass the earlier normalization path. An unauthenticated attacker who can influence an application's redirect target can send users to an attacker-controlled host for phishing or OAuth and SSO token theft, but exploitation requires the user to follow the redirect. This issue is fixed in version 1.8.11.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-20: 2Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-20: 208-20
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Patch

    CVE-2026-54770 WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI… https://www.cve.org/CVERecord?id=CVE-2026-54770

    Post summary

    The post cites the CVE‑2026‑54770 flaw in WebOb’s Request/Response handling, specifies the affected function, and indicates that version 1.8.11 provides a patch, with no evidence of exploitation or PoC.

    000101.2K
    58.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-54770 WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI… https://www.cve.org/CVERecord?id=CVE-2026-54770 ----- Traducción: CVE-2026-54770 Web… https://infoflow.cloud`

    Post summary

    The tweet briefly announces CVE‑2026‑54770 in WebOb, linking to the CVE record and giving technical details but does not provide a PoC, exploit code, or patch information.

    0000022
    102 followersView on X

Explore more