Sensitive Data Exposure in Erlang OTP HTTP Client
CVE-2026-48856

7.1HIGH

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-48856?

A vulnerability in the HTTP client of Erlang OTP allows sensitive data, including Authorization and Proxy-Authorization headers, to be exposed during cross-origin redirects. When the httpc client issues a redirect, it forwards these headers without verifying the legitimacy of the redirect target. This flaw can lead to credential theft, as an attacker controlling the redirect target can capture sensitive information that is meant for a different origin. The vulnerability affects all httpc callers that have automatic redirects enabled by default, impacting multiple versions of the Erlang OTP inets module.

Affected Version(s)

OTP 5.10

OTP 17.0

OTP 84adefa331c4159d432d22840663c38f155cd4c1 < 688d748d6f7a6a06b13b662a1d3de8af97079612

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonatan Männchen / EEF
Jonatan Männchen / EEF
Ingela Anderton Andin
Konrad Pietrzak
.