mediumCVSS 6.5Vulnerability
CVE-2026-54171
### Impact The redirect follower middleware previously failed to strip a number of headers that are known to be sensitive and did not provide a way to provide a custom list of headers to strip. _What kind of vulnerability is it? Who is impacted?_ This could cause inadvertent leakage of sensitive data for users of the RedirectFollower middleware in cases where the initial request includes header information that is not intended for the new target. ### Patches Patch exists and is released in v1.5.0 ### Workarounds Users can backport the [fix](https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3) to a custom redirect follower middleware.
Properties
- severity
- medium
- summary
- Excon does not redact additional sensitive/risky headers when following redirects
- epss_score
- 0.00427
- cvss_score
- 6.5
- ghsa_published
- 2026-07-10T20:37:29Z
- source_url
- https://github.com/advisories/GHSA-48rx-c7pg-q66r
- ghsa_updated
- 2026-07-10T20:37:32Z
- ghsa_id
- GHSA-48rx-c7pg-q66r
- cve_id
- CVE-2026-54171
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- is_ghsa_only
- false
- epss_percentile
- 0.35363
Related Entities (4)
ENRICHED_BY (1)
→[Source]FIRST EPSS
VULNERABLE_TO (1)
←[Software]rubygems/excon
AFFECTS (1)
→[Software]rubygems/excon
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph