Excon does not redact additional sensitive/risky headers when following redirects (CVE-2026-54171)
### Impact The redirect follower middleware previously failed to strip a number of headers that are known to be sensitive and did not provide a way to provide a custom list of headers to strip. _What kind of vulnerability is it? Who is impacted?_ This could cause inadvertent leakage of sensitive data for users of the RedirectFollower middleware in cases where the initial request includes header information that is not intended for the new target. ### Patches Patch exists and is released in v1.5.0 ### Workarounds Users can backport the [fix](https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3) to a custom redirect follower middleware.
AI Analysis
Technical Summary
The vulnerability in Excon's RedirectFollower middleware involves failure to strip multiple sensitive headers during HTTP redirect handling. Without redaction, headers containing sensitive data may be forwarded to new targets unintentionally, potentially exposing confidential information. The middleware also lacked the capability to customize which headers to strip. This issue affects versions prior to 1.5.0. A fix was introduced in version 1.5.0 to properly redact these headers and allow customization.
Potential Impact
Sensitive header information may be leaked to unintended redirect targets when using the vulnerable RedirectFollower middleware. This exposure could compromise confidentiality of sensitive data included in headers. There is no indication of impact on integrity or availability.
Mitigation Recommendations
Upgrade to Excon version 1.5.0 or later, where the issue is fixed with proper redaction of sensitive headers during redirects. Alternatively, users can backport the fix from the official patch commit to their own custom redirect follower middleware implementations. No other mitigation is indicated.
Excon does not redact additional sensitive/risky headers when following redirects (CVE-2026-54171)
Description
### Impact The redirect follower middleware previously failed to strip a number of headers that are known to be sensitive and did not provide a way to provide a custom list of headers to strip. _What kind of vulnerability is it? Who is impacted?_ This could cause inadvertent leakage of sensitive data for users of the RedirectFollower middleware in cases where the initial request includes header information that is not intended for the new target. ### Patches Patch exists and is released in v1.5.0 ### Workarounds Users can backport the [fix](https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3) to a custom redirect follower middleware.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Excon's RedirectFollower middleware involves failure to strip multiple sensitive headers during HTTP redirect handling. Without redaction, headers containing sensitive data may be forwarded to new targets unintentionally, potentially exposing confidential information. The middleware also lacked the capability to customize which headers to strip. This issue affects versions prior to 1.5.0. A fix was introduced in version 1.5.0 to properly redact these headers and allow customization.
Potential Impact
Sensitive header information may be leaked to unintended redirect targets when using the vulnerable RedirectFollower middleware. This exposure could compromise confidentiality of sensitive data included in headers. There is no indication of impact on integrity or availability.
Mitigation Recommendations
Upgrade to Excon version 1.5.0 or later, where the issue is fixed with proper redaction of sensitive headers during redirects. Alternatively, users can backport the fix from the official patch commit to their own custom redirect follower middleware implementations. No other mitigation is indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-48rx-c7pg-q66r
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-54171"]
- Ecosystems
- ["RubyGems"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a520eb168715ace438f4fec
Added to database: 07/11/2026, 09:36:49 UTC
Last enriched: 07/11/2026, 09:48:32 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 81
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.