CVE-2026-48856

EUVD-2026-36058
Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data.

The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking whether the redirect crosses an origin boundary. httpc_response:redirect/2 constructs the redirected request by updating only the host field of the header record; all other fields (including authorization and proxy_authorization) are copied verbatim. The redirect target host is never compared against the original host.

autoredirect defaults to true, so this affects all httpc callers that do not explicitly disable automatic redirects.

An attacker who controls a server that the victim contacts via httpc can issue a cross-origin 3xx redirect to a server they also control. The Authorization header (including Basic credentials derived from URL userinfo via httpc_request:handle_user_info/2) is forwarded to the redirect target, allowing credential theft. The same applies to the Proxy-Authorization header.

This vulnerability is associated with program files lib/inets/src/http_client/httpc_response.erl.

This issue affects OTP from OTP 17.0 before OTP 29.0.2, OTP 28.5.0.2 and OTP 27.3.4.13, corresponding to inets from 5.10 before 9.7.1, 9.6.2.2 and 9.3.2.6.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 26.37%
Affected Products (NVD)
VendorProductVersion
erlangerlang/inets
5.10 ≤
𝑥
< 9.3.2.6
erlangerlang/inets
9.6 ≤
𝑥
< 9.6.2.2
erlangerlang/inets
9.7 ≤
𝑥
< 9.7.1
erlangerlang/otp
17.0 ≤
𝑥
< 27.3.4.13
erlangerlang/otp
28.0 ≤
𝑥
< 28.5.0.2
erlangerlang/otp
29.0 ≤
𝑥
< 29.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
erlang
bookworm
vulnerable
bookworm (security)
vulnerable
forky
1:29.0.4+dfsg-1
fixed
sid
1:29.0.6+dfsg-1
fixed
trixie
vulnerable
trixie (security)
1:27.3.4.1+dfsg-1+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
erlang
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
erlang
suse enterprise sap 15 SP4
23.3.4.19-150300.3.39.1
fixed
suse enterprise sap 15 SP5
23.3.4.19-150300.3.39.1
fixed
suse enterprise sap 15 SP6
23.3.4.19-150300.3.39.1
fixed
suse enterprise sap 15 SP7
23.3.4.19-150300.3.39.1
fixed
suse enterprise server 15 SP4
23.3.4.19-150300.3.39.1
fixed
suse enterprise server 15 SP5
23.3.4.19-150300.3.39.1
fixed
suse enterprise server 15 SP6
23.3.4.19-150300.3.39.1
fixed
suse enterprise server 15 SP7
23.3.4.19-150300.3.39.1
fixed
erlang-epmd
suse enterprise sap 15 SP4
23.3.4.19-150300.3.39.1
fixed
suse enterprise sap 15 SP5
23.3.4.19-150300.3.39.1
fixed
suse enterprise sap 15 SP6
23.3.4.19-150300.3.39.1
fixed
suse enterprise sap 15 SP7
23.3.4.19-150300.3.39.1
fixed
suse enterprise server 15 SP4
23.3.4.19-150300.3.39.1
fixed
suse enterprise server 15 SP5
23.3.4.19-150300.3.39.1
fixed
suse enterprise server 15 SP6
23.3.4.19-150300.3.39.1
fixed
suse enterprise server 15 SP7
23.3.4.19-150300.3.39.1
fixed
erlang26
suse enterprise sap 15 SP6
26.2.1-150300.7.28.1
fixed
suse enterprise sap 15 SP7
26.2.1-150300.7.28.1
fixed
suse enterprise server 15 SP6
26.2.1-150300.7.28.1
fixed
suse enterprise server 15 SP7
26.2.1-150300.7.28.1
fixed
erlang26-epmd
suse enterprise sap 15 SP6
26.2.1-150300.7.28.1
fixed
suse enterprise sap 15 SP7
26.2.1-150300.7.28.1
fixed
suse enterprise server 15 SP6
26.2.1-150300.7.28.1
fixed
suse enterprise server 15 SP7
26.2.1-150300.7.28.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
erlang
Azure Linux 3.0
0:26.2.5.21-2.azl3
fixed