MEDIUM 6.5 RubyGems

Excon does not redact additional sensitive/risky headers when following redirects

GHSA-48rx-c7pg-q66r · CVE-2026-54171

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

The redirect follower middleware previously failed to strip a number of headers that are known to be sensitive and did not provide a way to provide a custom list of headers to strip.

What kind of vulnerability is it? Who is impacted?
This could cause inadvertent leakage of sensitive data for users of the RedirectFollower middleware in cases where the initial request includes header information that is not intended for the new target.

Patches

Patch exists and is released in v1.5.0

Workarounds

Users can backport the fix to a custom redirect follower middleware.

Ready to move

Start Securing

Free, no credit card | First findings in minutes