Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59180

Опубликовано: 10 июл. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and config loaders in apprise/attachment/http.py and apprise/config/http.py follow HTTP redirects by default and resend user-configured auth headers and query parameters on the redirected request, allowing a compromised trusted destination or on-path attacker to receive secrets such as Authorization headers, bearer tokens, custom headers, and service keys. This issue is fixed in version 1.11.0.

A flaw was found in Apprise, an open-source library for sending notifications. HTTP-based notification plugins and HTTP attachment and configuration loaders in Apprise, prior to version 1.11.0, automatically follow HTTP redirects. During these redirects, user-configured authentication headers and query parameters are resent. This could allow a compromised trusted destination or an attacker on the network path to intercept sensitive information, such as authentication tokens and service keys, leading to information disclosure.

Отчет

This flaw affects the community-maintained python-apprise package as shipped in Fedora and EPEL. Red Hat does not ship Apprise in any core Red Hat product. HTTP-based notification plugins and HTTP attachment/config loaders followed redirects by default and resent user-configured authentication headers and query parameters, allowing a compromised trusted destination or on-path attacker to capture secrets such as bearer tokens and service keys. Fedora already ships the fixed version (1.11.0); EPEL 8 still ships the vulnerable 1.7.5 build.

Меры по смягчению последствий

Users of python-apprise on EPEL 8 should upgrade to 1.11.0 or later, which no longer resends authentication headers or query parameters on HTTP redirects. There is no server-side workaround; avoiding notification targets that are untrusted or capable of issuing redirects reduces exposure until the package is updated.

Дополнительная информация

Статус:

Low
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2499082apprise: Apprise: Information disclosure via HTTP redirect following with credential resending

EPSS

Процентиль: 9%
0.00195
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
24 дня назад

Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and config loaders in apprise/attachment/http.py and apprise/config/http.py follow HTTP redirects by default and resend user-configured auth headers and query parameters on the redirected request, allowing a compromised trusted destination or on-path attacker to receive secrets such as Authorization headers, bearer tokens, custom headers, and service keys. This issue is fixed in version 1.11.0.

CVSS3: 3.1
nvd
24 дня назад

Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and config loaders in apprise/attachment/http.py and apprise/config/http.py follow HTTP redirects by default and resend user-configured auth headers and query parameters on the redirected request, allowing a compromised trusted destination or on-path attacker to receive secrets such as Authorization headers, bearer tokens, custom headers, and service keys. This issue is fixed in version 1.11.0.

CVSS3: 3.1
debian
24 дня назад

Apprise is an open source library which allows you to send a notificat ...

EPSS

Процентиль: 9%
0.00195
Низкий

3.1 Low

CVSS3