Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-54171

Опубликовано: 17 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0.

EPSS

Процентиль: 23%
0.00304
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-201

Связанные уязвимости

CVSS3: 6.5
ubuntu
14 дней назад

(Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon ...)

CVSS3: 6.5
msrc
14 дней назад

Excon: redact additional sensitive/risky headers when following redirects

CVSS3: 6.5
debian
16 дней назад

Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon ...

CVSS3: 6.5
github
23 дня назад

Excon does not redact additional sensitive/risky headers when following redirects

EPSS

Процентиль: 23%
0.00304
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-201