mediumCVSS 6.5Vulnerability

CVE-2026-54171

### Impact The redirect follower middleware previously failed to strip a number of headers that are known to be sensitive and did not provide a way to provide a custom list of headers to strip. _What kind of vulnerability is it? Who is impacted?_ This could cause inadvertent leakage of sensitive data for users of the RedirectFollower middleware in cases where the initial request includes header information that is not intended for the new target. ### Patches Patch exists and is released in v1.5.0 ### Workarounds Users can backport the [fix](https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3) to a custom redirect follower middleware.

Properties

severity
medium
summary
Excon does not redact additional sensitive/risky headers when following redirects
epss_score
0.00427
cvss_score
6.5
ghsa_published
2026-07-10T20:37:29Z
source_url
https://github.com/advisories/GHSA-48rx-c7pg-q66r
ghsa_updated
2026-07-10T20:37:32Z
ghsa_id
GHSA-48rx-c7pg-q66r
cve_id
CVE-2026-54171
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
is_ghsa_only
false
epss_percentile
0.35363

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]rubygems/excon

AFFECTS (1)

[Software]rubygems/excon

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph