UBUNTU-CVE-2026-59180
Apprise versions prior to 1.11.0 have a vulnerability in their HTTP-based notification plugins and HTTP attachment and config loaders where HTTP redirects are followed by default, causing user-configured authorization headers and query parameters to be resent to redirected destinations. This behavior can expose sensitive information such as Authorization headers, bearer tokens, custom headers, and service keys to a compromised or malicious redirect endpoint. The issue is fixed in Apprise version 1.11.0.
AI Analysis
Technical Summary
Apprise is an open source notification library. Versions before 1.11.0 have a security flaw in HTTP-based notification plugins and HTTP attachment/config loaders (specifically in apprise/attachment/http.py and apprise/config/http.py) where HTTP redirects are automatically followed and user-configured authentication headers and query parameters are resent to the redirected URL. This can leak sensitive secrets to an attacker controlling the redirect destination or an on-path attacker. The vulnerability is resolved in version 1.11.0.
Potential Impact
Sensitive authentication information including Authorization headers, bearer tokens, custom headers, and service keys can be exposed to an attacker controlling a redirect destination or positioned on the network path. This leakage may allow unauthorized access to notification services or other resources relying on these secrets. There is no indication of direct code execution or denial of service impact.
Mitigation Recommendations
Upgrade Apprise to version 1.11.0 or later where this issue is fixed. No other mitigations are indicated by the vendor advisory.
UBUNTU-CVE-2026-59180
Description
Apprise versions prior to 1.11.0 have a vulnerability in their HTTP-based notification plugins and HTTP attachment and config loaders where HTTP redirects are followed by default, causing user-configured authorization headers and query parameters to be resent to redirected destinations. This behavior can expose sensitive information such as Authorization headers, bearer tokens, custom headers, and service keys to a compromised or malicious redirect endpoint. The issue is fixed in Apprise version 1.11.0.
CVSS v3.1
Score 3.1low
Affected software
pkg:deb/ubuntu/[email protected]?arch=source&distro=nobleRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apprise is an open source notification library. Versions before 1.11.0 have a security flaw in HTTP-based notification plugins and HTTP attachment/config loaders (specifically in apprise/attachment/http.py and apprise/config/http.py) where HTTP redirects are automatically followed and user-configured authentication headers and query parameters are resent to the redirected URL. This can leak sensitive secrets to an attacker controlling the redirect destination or an on-path attacker. The vulnerability is resolved in version 1.11.0.
Potential Impact
Sensitive authentication information including Authorization headers, bearer tokens, custom headers, and service keys can be exposed to an attacker controlling a redirect destination or positioned on the network path. This leakage may allow unauthorized access to notification services or other resources relying on these secrets. There is no indication of direct code execution or denial of service impact.
Mitigation Recommendations
Upgrade Apprise to version 1.11.0 or later where this issue is fixed. No other mitigations are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-59180
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a58b45968715ace43d6bbf8
Added to database: 07/16/2026, 10:37:13 UTC
Last enriched: 07/16/2026, 11:34:28 UTC
Last updated: 07/31/2026, 19:24:47 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.