CVE-2026-55403

LOW

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

Title source: cna
STIX 2.1

Description

datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_generator/http.py get_body reuses Authorization, Cookie, and Proxy-Authorization headers when following cross-origin redirects while fetching remote schemas, allowing credentials scoped to one schema host to be leaked to another redirect target. This issue is fixed in version 0.63.0.

Scores

CVSS v3 3.7
EPSS 0.0021
EPSS Percentile 11.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-601
Status published
Products (2)
koxudaxi/datamodel-code-generator < 0.63.0
pypi/datamodel-code-generator 0 - 0.63.0PyPI
Published Jul 28, 2026
Tracked Since Jul 29, 2026