{"id":"CVE-2026-55403","aliases":["GHSA-r5vv-ff45-prp2","PYSEC-2026-3563"],"url":"https://o3.security/vulnerability/CVE-2026-55403","summary":"datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas","details":"datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_generator/http.py get_body reuses Authorization, Cookie, and Proxy-Authorization headers when following cross-origin redirects while fetching remote schemas, allowing credentials scoped to one schema host to be leaked to another redirect target. This issue is fixed in version 0.63.0.","published":"2026-07-28T21:31:49.172Z","modified":"2026-09-13T11:45:15.071322911Z","cvss":{"score":3.7,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":{"score":0.00211,"percentile":0.11411,"asOf":"2026-09-11"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"datamodel-code-generator","fixedVersion":"0.63.0"}],"fix":{"url":"https://github.com/koxudaxi/datamodel-code-generator/commit/a585c037c8307b7aae815de193b7fe1c4c44994b","label":"koxudaxi/datamodel-code-generator@a585c03"},"references":[{"type":"WEB","url":"https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.63.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55403.json"},{"type":"ADVISORY","url":"https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-r5vv-ff45-prp2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55403"},{"type":"FIX","url":"https://github.com/koxudaxi/datamodel-code-generator/commit/a585c037c8307b7aae815de193b7fe1c4c44994b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-13T11:45:15.071322911Z"}}