Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-54171

Опубликовано: 17 июл. 2026
Источник: debian
EPSS Низкий

Описание

Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby-exconfixed1.5.0-1package

Примечания

  • https://github.com/excon/excon/security/advisories/GHSA-48rx-c7pg-q66r

  • https://github.com/excon/excon/pull/901

  • Fixed by: https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3 (v1.5.0)

EPSS

Процентиль: 23%
0.00304
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
16 дней назад

Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0.

CVSS3: 6.5
nvd
16 дней назад

Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0.

CVSS3: 6.5
msrc
14 дней назад

Excon: redact additional sensitive/risky headers when following redirects

CVSS3: 6.5
github
23 дня назад

Excon does not redact additional sensitive/risky headers when following redirects

EPSS

Процентиль: 23%
0.00304
Низкий