GHSA-x426-x7cc-3fpc
MODERATECVE-2026-48022Wreck strips credential headers (Authorization, Cookie, Proxy-Authorization) before following a cross-origin redirect, but the origin check compares hostnames only and ignores scheme and port. As a result, credentials are forwarded intact across same-host port changes and HTTPS-to-HTTP downgrades, allowing a co-tenant on an adjacent port or a network-position attacker capable of forging a redirect
- Affected
- >=0, <18.1.2, < 18.1.2
- Fixed in
- 18.1.2
- Weakness
- CWE-200
- Published
- 2026-06-11
- Source
- osv