CVE-2026-59180: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in caronc apprise
Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and config loaders in apprise/attachment/http.py and apprise/config/http.py follow HTTP redirects by default and resend user-configured auth headers and query parameters on the redirected request, allowing a compromised trusted destination or on-path attacker to receive secrets such as Authorization headers, bearer tokens, custom headers, and service keys. This issue is fixed in version 1.11.0.
AI Analysis
Technical Summary
CVE-2026-59180 affects the Apprise open source notification library before version 1.11.0. The vulnerability arises because HTTP-based notification plugins and HTTP attachment/config loaders automatically follow HTTP redirects and resend user-configured authentication headers and query parameters on the redirected requests. This can lead to exposure of sensitive information including Authorization headers, bearer tokens, custom headers, and service keys to an attacker controlling the redirect destination or positioned on the network path. The vulnerability is categorized under CWE-200 (Exposure of Sensitive Information) and CWE-601 (Open Redirect). The issue is resolved in Apprise version 1.11.0.
Potential Impact
Sensitive authentication information such as Authorization headers, bearer tokens, custom headers, and service keys may be exposed to unauthorized actors if they can control or intercept HTTP redirects. This could lead to information disclosure but does not directly impact integrity or availability. The CVSS v3.1 score is 3.1, indicating a low severity impact with network attack vector, high attack complexity, no privileges required, and user interaction needed.
Mitigation Recommendations
Upgrade Apprise to version 1.11.0 or later, where the issue is fixed. No other mitigation is specified or required as the vulnerability is resolved in this official fix.
CVE-2026-59180: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in caronc apprise
Description
Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and config loaders in apprise/attachment/http.py and apprise/config/http.py follow HTTP redirects by default and resend user-configured auth headers and query parameters on the redirected request, allowing a compromised trusted destination or on-path attacker to receive secrets such as Authorization headers, bearer tokens, custom headers, and service keys. This issue is fixed in version 1.11.0.
CVSS v3.1
Score 3.1low
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-59180 affects the Apprise open source notification library before version 1.11.0. The vulnerability arises because HTTP-based notification plugins and HTTP attachment/config loaders automatically follow HTTP redirects and resend user-configured authentication headers and query parameters on the redirected requests. This can lead to exposure of sensitive information including Authorization headers, bearer tokens, custom headers, and service keys to an attacker controlling the redirect destination or positioned on the network path. The vulnerability is categorized under CWE-200 (Exposure of Sensitive Information) and CWE-601 (Open Redirect). The issue is resolved in Apprise version 1.11.0.
Potential Impact
Sensitive authentication information such as Authorization headers, bearer tokens, custom headers, and service keys may be exposed to unauthorized actors if they can control or intercept HTTP redirects. This could lead to information disclosure but does not directly impact integrity or availability. The CVSS v3.1 score is 3.1, indicating a low severity impact with network attack vector, high attack complexity, no privileges required, and user interaction needed.
Mitigation Recommendations
Upgrade Apprise to version 1.11.0 or later, where the issue is fixed. No other mitigation is specified or required as the vulnerability is resolved in this official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-02T19:53:48.830Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a511ed668715ace43d68a16
Added to database: 07/10/2026, 16:33:26 UTC
Last enriched: 07/10/2026, 16:48:07 UTC
Last updated: 08/23/2026, 22:52:12 UTC
Views: 82
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.