{"id":"CVE-2026-50192","summary":"Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirect","details":"Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` request headers to the operator-configured Hub URL (`config.HubURI`). The HTTP client used (`&http.Client{}` in `UploadKerberosHub`) is constructed without a `CheckRedirect` policy, so it follows HTTP redirects automatically. Go's `net/http` strips only sensitive headers (`Authorization`, `Cookie`, `WWW-Authenticate`) on a cross-host redirect; it does not strip custom headers such as `X-Kerberos-Hub-PrivateKey`. As a result, if the configured `HubURI` returns a cross-host 30x redirect, the Hub private key is forwarded verbatim to the redirect target, disclosing the credential to an unintended third party. Version 3.6.26 fixes the issue by implementing the `CheckRedirect` strip plus a cross-host regression test is provided to the maintainer through the advisory's private temporary fork.","aliases":["GHSA-h5gx-45rj-2h5j","GO-2026-5890"],"modified":"2026-08-23T03:42:58.321728781Z","published":"2026-08-20T21:37:20.598Z","related":["openSUSE-SU-2026:21483-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-200","CWE-522"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50192.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50192.json"},{"type":"ADVISORY","url":"https://github.com/kerberos-io/agent/security/advisories/GHSA-h5gx-45rj-2h5j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50192"},{"type":"FIX","url":"https://github.com/kerberos-io/agent/commit/51f1a52e170f21c1264c6de1dc781d5b5e2a5d09"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kerberos-io/agent","events":[{"introduced":"0"},{"fixed":"51f1a52e170f21c1264c6de1dc781d5b5e2a5d09"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"3.6.26"}]}}],"versions":["v3.6.25","v3.6.24","v3.6.23","v3.6.22","v3.6.21","v3.6.20","v3.6.19","v3.6.18","v3.6.17","v3.6.16","v3.6.15","v3.6.14","v3.6.13","v3.6.12","v3.6.11","v3.6.10","v3.6.9","v3.6.8","v3.6.7","v3.6.6","v3.6.5","v3.6.4","v3.6.3","v3.6.2","v3.6.1","v3.6.0","v3.3.21","v3.3.20","v3.5.6","v3.5.5","v3.5.4","v3.5.3","v3.5.2","v3.5.1","v3.5.0","v3.4.4","v3.4.3","v3.4.2","v3.4.1","v3.4.0","v3.3.19-onvif-v0.0.14","v3.3.19","v3.3.18","v3.3.17","v3.3.16","v3.3.15","v3.3.14","v3.3.13","v3.3.12","v3.3.11","v3.3.10","v3.3.9","v3.3.8","v3.3.7","v3.3.5","v3.3.4","v3.3.3","v3.3.2","v3.3.1","v3.3.0","v3.2.10","v3.2.9","v3.2.8","v3.2.7","v3.2.6","v3.2.5","v3.2.4","3.2.3","3.2.2","3.2.1","3.2.0","ca24133","b67a72b","4c41301","21d81b9","14d38ec","83ba7ba","9339ae3","442ba97","aac2150","751aa17","2681bd2","ca36761","f739d52","c278a66","fa91e84","6672535","ed397b6","530e4c6","913bd1b","84e532b","3341e99","ced6e67","60e8edc","9cf9bab","229c246","15d9bcd","0680636","b172284","eb5ab48","b64f103","6fcd6e5","25537b5","2fad541","afefd32","02f3e6a","2860775","d6ba875","e9ea34c","99cc7d4","1a6dc27","93f40a8","d7f7de9","4352d99","026bf93","bbbed49","87f681c","f935360","71cd315","d9694ac","192f78a","af95c0f","31a0b9e","4a4aabd","b058c1e","7671b1c","4cc8135","3cb3809","deb0308","24c729e","c59d511","6f8745d","65d3d64","b4a8028","9d70778","2feda33","ec42b9e","a2b4ee1","a0f99a5","9aff467","926f9ea","43d12ee","7e6b698","4aa8ce7","be02774","d4e1008","898a118","a098052","v1.0.0-beta","v0.0.1-alpha"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50192.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}