{"id":"EEF-CVE-2026-48856","summary":"httpc leaks Authorization header to cross-origin redirect targets","details":"## Summary\n\nSensitive Data Exposure vulnerability in Erlang OTP inets (`httpc_response` module) allows Retrieve Embedded Sensitive Data.\n\nThe `httpc` client forwards the `Authorization` and `Proxy-Authorization` request headers to redirect targets without checking whether the redirect crosses an origin boundary. `httpc_response:redirect/2` constructs the redirected request by updating only the `host` field of the header record; all other fields (including `authorization` and `proxy_authorization`) are copied verbatim. The redirect target host is never compared against the original host.\n\n`autoredirect` defaults to `true`, so this affects all `httpc` callers that do not explicitly disable automatic redirects.\n\nAn attacker who controls a server that the victim contacts via `httpc` can issue a cross-origin 3xx redirect to a server they also control. The `Authorization` header (including Basic credentials derived from URL userinfo via `httpc_request:handle_user_info/2`) is forwarded to the redirect target, allowing credential theft. The same applies to the `Proxy-Authorization` header.\n\nThis vulnerability is associated with program files `lib/inets/src/http_client/httpc_response.erl`.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to inets from 5.10 before 9.3.2.6, 9.6.2.2, and 9.7.1. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.\n\n## Workarounds\n\n* Set `{autoredirect, false}` in the `httpc:request/4` options and handle redirects manually, stripping the `Authorization` header when the redirect crosses an origin boundary.\n* Ensure that `httpc` is only used to contact trusted servers that will not issue cross-origin redirects.","aliases":["CVE-2026-48856","GHSA-m75x-4vwg-ggjh"],"modified":"2026-09-24T20:45:42.194995603Z","published":"2026-06-10T14:41:51.616Z","database_specific":{"capec_ids":["CAPEC-37"],"cpe_ids":["cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"],"cwe_ids":["CWE-601"]},"references":[{"type":"ADVISORY","url":"https://github.com/erlang/otp/security/advisories/GHSA-m75x-4vwg-ggjh"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-48856.html"},{"type":"WEB","url":"https://www.erlang.org/doc/system/versions.html#order-of-versions"},{"type":"FIX","url":"https://github.com/erlang/otp/commit/688d748d6f7a6a06b13b662a1d3de8af97079612"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/erlang/otp","events":[{"introduced":"84adefa331c4159d432d22840663c38f155cd4c1"},{"fixed":"688d748d6f7a6a06b13b662a1d3de8af97079612"}]}],"versions":["patch-base-27","OTP-27.3.4","OTP-27.0","OTP-27.3","OTP-27.3.3","OTP-26.0","OTP-25.0","OTP-27.3.2","OTP-27.2","OTP-27.3.1","OTP-27.1","OTP-27.0-rc3","OTP-27.0-rc2","OTP-27.0-rc1","OTP-24.0","OTP-26.0-rc3","OTP-26.0-rc2","OTP-26.0-rc1","OTP-23.0","OTP-21.0","OTP-25.0-rc3","OTP-25.0-rc2","OTP-25.0-rc1","OTP-22.0","OTP-24.0-rc3","OTP-24.0-rc2","OTP-24.0-rc1","OTP-23.0-rc3","OTP-23.0-rc2","OTP-23.0-rc1","OTP-20.0","OTP-22.0-rc3","OTP-22.0-rc2","OTP-22.0-rc1","OTP-19.0","OTP-21.0-rc2","OTP-18.0","OTP-21.0-rc1","OTP-17.0","OTP-20.0-rc2","OTP-20.0-rc1","OTP-19.0-rc2","OTP-19.0-rc1","OTP_R16B","OTP-18.0-rc1","OTP_17.0-rc2","OTP_17.0-rc1","OTP_R13B03","OTP_R16A_RELEASE_CANDIDATE","OTP_R14B03","OTP_R15B","OTP_R15A","OTP_R14B02","OTP_R14B01","OTP_R14B","OTP_R13B04","OTP_R14A"],"database_specific":{"source":"https://cna.erlef.org/osv/EEF-CVE-2026-48856.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}],"credits":[{"name":"Jonatan Männchen / EEF","type":"FINDER"},{"name":"Jonatan Männchen / EEF","type":"REMEDIATION_DEVELOPER"},{"name":"Ingela Anderton Andin","type":"REMEDIATION_REVIEWER"},{"name":"Konrad Pietrzak","type":"REMEDIATION_REVIEWER"}]}