Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91766

Опубликовано: 25 сент. 2026
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f ).

EPSS

Процентиль: 25%
0.00338
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.9
ubuntu
8 дней назад

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f ).

CVSS3: 5.9
redhat
8 дней назад

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HTTPS to HTTP. A server that can steer a redirect therefore receives credentials that were only meant for the original origin. This is the same class of issue that libcurl fixed in 7.58.0 ( CVE-2018-1000007 https://github.com/advisories/GHSA-g7x2-hrfp-pv5f ).

CVSS3: 5.9
msrc
4 дня назад

Cross-origin credential leak in HTTP stream wrapper redirects

CVSS3: 5.9
debian
8 дней назад

When the http:// stream wrapper follows a redirect it forwards the use ...

CVSS3: 5.9
github
9 дней назад

Cross-origin credential leak in HTTP stream wrapper redirects

EPSS

Процентиль: 25%
0.00338
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-200