CVE-2026-48856: httpc leaks Authorization header to cross-origin redirect targets

Published Jun 10, 2026
·
Updated

httpc leaks Authorization header to cross-origin redirect targets

Other sources

Sensitive Data Exposure vulnerability in Erlang OTP inets (httpcresponse module) allows Retrieve Embedded Sensitive Data.

The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking whether the redirect crosses an origin boundary. httpcresponse:redirect/2 constructs the redirected request by updating only the host field of the header record; all other fields (including authorization and proxyauthorization) are copied verbatim. The redirect target host is never compared against the original host.

autoredirect defaults to true, so this affects all httpc callers that do not explicitly disable automatic redirects.

An attacker who controls a server that the victim contacts via httpc can issue a cross-origin 3xx redirect to a server they also control. The Authorization header (including Basic credentials derived from URL userinfo via httpcrequest:handleuserinfo/2) is forwarded to the redirect target, allowing credential theft. The same applies to the Proxy-Authorization header.

This vulnerability is associated with program files lib/inets/src/httpclient/httpcresponse.erl.

This issue affects OTP from 17.0 before 29.0.2, 28.5.0.2 and 27.3.4.13 corresponding to inets from 5.10 before 9.7.1, 9.6.2.2 and 9.3.2.6.

NVD

Sensitive Data Exposure vulnerability in Erlang OTP inets (httpcresponse module) allows Retrieve Embedded Sensitive Data.

The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking whether the redirect crosses an origin boundary. httpcresponse:redirect/2 constructs the redirected request by updating only the host field of the header record; all other fields (including authorization and proxyauthorization) are copied verbatim. The redirect target host is never compared against the original host.

autoredirect defaults to true, so this affects all httpc callers that do not explicitly disable automatic redirects.

An attacker who controls a server that the victim contacts via httpc can issue a cross-origin 3xx redirect to a server they also control. The Authorization header (including Basic credentials derived from URL userinfo via httpcrequest:handleuserinfo/2) is forwarded to the redirect target, allowing credential theft. The same applies to the Proxy-Authorization header.

This vulnerability is associated with program files lib/inets/src/httpclient/httpcresponse.erl.

This issue affects OTP from OTP 17.0 before OTP 29.0.2, OTP 28.5.0.2 and OTP 27.3.4.13, corresponding to inets from 5.10 before 9.7.1, 9.6.2.2 and 9.3.2.6.

MITRE

Affected Software

9 affected componentsFixes available
Erlang OTP>=17.0<29.0.2, >=17.0<28.5.0.2, >=17.0<27.3.4.13
Erlang inets>=5.10<9.7.1, >=5.10<9.6.2.2, >=5.10<9.3.2.6
Erlang Erlang\/inets>=5.10<9.3.2.6
Erlang Erlang\/inets>=9.6<9.6.2.2
Erlang Erlang\/inets>=9.7<9.7.1
Erlang Erlang\/otp>=17.0<27.3.4.13
Erlang Erlang\/otp>=28.0<28.5.0.2
Erlang Erlang\/otp>=29.0<29.0.2
Microsoft azl3 erlang 26.2.5.20-1<26.2.5.21-2
26.2.5.21-2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 26.2.5.21-2
  2. Upgrade

    Upgrade Erlang OTP (inets/httpc, httpc_response module) to a version that resolves this vulnerability.

    Fixed in 29.0.2
  3. Upgrade

    Upgrade Erlang OTP (inets/httpc, httpc_response module) to a version that resolves this vulnerability.

    Fixed in 28.5.0.2
  4. Upgrade

    Upgrade Erlang OTP (inets/httpc, httpc_response module) to a version that resolves this vulnerability.

    Fixed in 27.3.4.13
  5. Configuration

    Disable automatic redirects in httpc callers by setting autoredirect to false, since autoredirect defaults to true and causes Authorization/Proxy-Authorization to be forwarded to cross-origin 3xx redirect targets.

    Erlang OTP httpc autoredirect = false

Event History

Jun 10, 2026
CVE Published
via MITRE·02:41 PM
Data Sourced
via MITRE·02:41 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 17, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:01 AM
Affected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-48856?

CVE-2026-48856 has a high severity rating of 7.1 according to the CVSS.

2

What kind of data is exposed in CVE-2026-48856?

CVE-2026-48856 exposes sensitive data such as the Authorization and Proxy-Authorization headers.

3

How does CVE-2026-48856 impact user privacy?

CVE-2026-48856 can lead to unauthorized access to sensitive information because it leaks headers to cross-origin redirect targets.

4

Which software is affected by CVE-2026-48856?

CVE-2026-48856 affects Erlang OTP, specifically the inets httpc_response module.

5

How do I fix CVE-2026-48856?

To mitigate CVE-2026-48856, update to a patched version of Erlang OTP that addresses the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203