Sensitive Data Exposure in Erlang OTP HTTP Client
CVE-2026-48856
What is CVE-2026-48856?
A vulnerability in the HTTP client of Erlang OTP allows sensitive data, including Authorization and Proxy-Authorization headers, to be exposed during cross-origin redirects. When the httpc client issues a redirect, it forwards these headers without verifying the legitimacy of the redirect target. This flaw can lead to credential theft, as an attacker controlling the redirect target can capture sensitive information that is meant for a different origin. The vulnerability affects all httpc callers that have automatic redirects enabled by default, impacting multiple versions of the Erlang OTP inets module.
Affected Version(s)
OTP 5.10
OTP 17.0
OTP 84adefa331c4159d432d22840663c38f155cd4c1 < 688d748d6f7a6a06b13b662a1d3de8af97079612
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
