
CVE-2026-54770 WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI… https://www.cve.org/CVERecord?id=CVE-2026-54770
Post summary
The post cites the CVE‑2026‑54770 flaw in WebOb’s Request/Response handling, specifies the affected function, and indicates that version 1.8.11 provides a patch, with no evidence of exploitation or PoC.

