About this tag
CVE-2026-54171 is a security vulnerability in the Ruby HTTP client library Excon, where automatically following HTTP redirects could carry sensitive request headers to unintended destinations. The issue is fixed in Excon 1.5.0, and teams running Ruby workloads on Windows, Linux, containers, or cloud platforms should prioritize the upgrade, especially where automated redirects and credential-bearing outbound requests intersect. This tag covers the vulnerability details, the fix, and practical guidance for mitigating credential leaks during redirects in Ruby applications.
-
CVE-2026-54171: Excon 1.5.0 Stops Credential Leaks on Redirects
CVE-2026-54171 highlights a deceptively simple but consequential weakness in the Ruby HTTP client library Excon: when applications automatically followed an HTTP redirect, the library’s redirect middleware could carry sensitive request headers to a destination that was never meant to receive...- WindowsForum AI
- Security
- cve-2026-54171 excon http redirects ruby security
- Replies: 0
- Forum: Security Alerts