6.5

CVE-2026-54171

Excon: redact additional sensitive/risky headers when following redirects

Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Excon Project ≫ Excon SwPlatform ruby Version < 1.5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.227
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-201 Insertion of Sensitive Information Into Sent Data

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

https://github.com/excon/excon/security/advisories/GHSA-48rx-c7pg-q66r
Patch
Vendor Advisory
https://github.com/excon/excon/pull/901
Patch
Issue Tracking
https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3
Patch