CVE-2026-48595: CWE-178 Improper Handling of Case Sensitivity in elixir-tesla tesla
A vulnerability in elixir-tesla tesla (version 1.4.0) allows credential leakage due to improper handling of case sensitivity in HTTP headers during cross-origin redirects. The middleware FollowRedirects uses a case-sensitive comparison to strip sensitive headers, but HTTP headers are case-insensitive per RFC 7230. This causes headers like "Authorization" with canonical casing to bypass filtering and be sent to unintended third-party origins.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-48595) in elixir-tesla tesla affects version 1.4.0 and involves Tesla.Middleware.FollowRedirects improperly handling case sensitivity when filtering security-sensitive headers on cross-origin redirects. The filter list uses lowercase header names ("authorization", "host") and compares them case-sensitively against headers as supplied by the caller, which preserves original casing. Since HTTP headers are case-insensitive, headers such as {"Authorization", "Bearer ..."} do not match the lowercase filter and are forwarded to the redirect destination. This can lead to leakage of bearer tokens or other authorization credentials to third-party origins if an attacker controls or influences the redirect location.
Potential Impact
An attacker who can control or influence the Location header in a redirect response can receive sensitive authorization credentials (e.g., bearer tokens) forwarded to a third-party origin. This results in credential leakage and potential unauthorized access. The vulnerability has a high severity with a CVSS 4.0 score of 8.2, indicating a significant risk if exploited.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using vulnerable versions or implement custom middleware to normalize header casing before redirects to ensure sensitive headers are properly stripped.
CVE-2026-48595: CWE-178 Improper Handling of Case Sensitivity in elixir-tesla tesla
Description
A vulnerability in elixir-tesla tesla (version 1.4.0) allows credential leakage due to improper handling of case sensitivity in HTTP headers during cross-origin redirects. The middleware FollowRedirects uses a case-sensitive comparison to strip sensitive headers, but HTTP headers are case-insensitive per RFC 7230. This causes headers like "Authorization" with canonical casing to bypass filtering and be sent to unintended third-party origins.
CVSS v4.0
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-48595) in elixir-tesla tesla affects version 1.4.0 and involves Tesla.Middleware.FollowRedirects improperly handling case sensitivity when filtering security-sensitive headers on cross-origin redirects. The filter list uses lowercase header names ("authorization", "host") and compares them case-sensitively against headers as supplied by the caller, which preserves original casing. Since HTTP headers are case-insensitive, headers such as {"Authorization", "Bearer ..."} do not match the lowercase filter and are forwarded to the redirect destination. This can lead to leakage of bearer tokens or other authorization credentials to third-party origins if an attacker controls or influences the redirect location.
Potential Impact
An attacker who can control or influence the Location header in a redirect response can receive sensitive authorization credentials (e.g., bearer tokens) forwarded to a third-party origin. This results in credential leakage and potential unauthorized access. The vulnerability has a high severity with a CVSS 4.0 score of 8.2, indicating a significant risk if exploited.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using vulnerable versions or implement custom middleware to normalize header casing before redirects to ensure sensitive headers are properly stripped.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-05-22T09:36:56.834Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a1f3494e29bf47b50fa2531
Added to database: 06/02/2026, 19:52:52 UTC
Last enriched: 07/10/2026, 09:32:13 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 109
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.