CVE-2026-48856

HIGH EPSS 25.4%
Published Jun 10, 20262w ago · Modified Jun 17, 20261w ago
7.1 CVSS 4.0
High
Find Similar
Published Jun 10, 2026 2w ago
Last Modified Jun 17, 2026 1w ago

Description

Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking whether the redirect crosses an origin boundary. httpc_response:redirect/2 constructs the redirected request by updating only the host field of the header record; all other fields (including authorization and proxy_authorization) are copied verbatim. The redirect target host is never compared against the original host. autoredirect defaults to true, so this affects all httpc callers that do not explicitly disable automatic redirects. An attacker who controls a server that the victim contacts via httpc can issue a cross-origin 3xx redirect to a server they also control. The Authorization header (including Basic credentials derived from URL userinfo via httpc_request:handle_user_info/2) is forwarded to the redirect target, allowing credential theft. The same applies to the Proxy-Authorization header. This vulnerability is associated with program files lib/inets/src/http_client/httpc_response.erl. This issue affects OTP from 17.0 before 29.0.2, 28.5.0.2 and 27.3.4.13 corresponding to inets from 5.10 before 9.7.1, 9.6.2.2 and 9.3.2.6.

CVSS Details

Base Score
7.1
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction P
Scope X

Threat Intelligence

EPSS Exploit Probability
25.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-601

Affected Products 6

VendorProductVersionRange
erlangerlang\/inets*≥5.10  –  <9.3.2.6
erlangerlang\/inets*≥9.6  –  <9.6.2.2
erlangerlang\/inets*≥9.7  –  <9.7.1
erlangerlang\/otp*≥17.0  –  <27.3.4.13
erlangerlang\/otp*≥28.0  –  <28.5.0.2
erlangerlang\/otp*≥29.0  –  <29.0.2

References 5

  • cna.erlef.org https://cna.erlef.org/cves/CVE-2026-48856.html
    MitigationThird Party Advisory
  • github.com https://github.com/erlang/otp/commit/688d748d6f7a6a06b13b662a1d3de8af97079612
    Patch
  • github.com https://github.com/erlang/otp/security/advisories/GHSA-m75x-4vwg-ggjh
    MitigationVendor Advisory
  • osv.dev https://osv.dev/vulnerability/EEF-CVE-2026-48856
    MitigationThird Party Advisory
  • erlang.org https://www.erlang.org/doc/system/versions.html#order-of-versions
    Product

Remediation

  • github.com https://github.com/erlang/otp/commit/688d748d6f7a6a06b13b662a1d3de8af97079612
    Patch