{"id":"CVE-2026-54171","title":"excon: Excon: Information disclosure via unstripped sensitive headers during redirects (CVE-2026-54171)","summary":"A flaw was found in Excon, a Ruby HTTP client library. The RedirectFollower middleware, responsible for handling redirects, failed to remove sensitive header information when a request was redirected to a new target. This oversight could l…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","cvssSource":"vendor","cwe":"CWE-212","vendor":"Red Hat","product":"Red Hat 3scale API Management Platform 2","affected":["3scale_api_management_platform 2","satellite 6"],"patched":["excon 1.5.0"],"published":"2026-07-17","updated":"2026-09-07","sourceUpdated":"2026-09-07T13:03:52+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54171.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54171.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-54171"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2501952"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-54171"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54171"},{"url":"https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3"},{"url":"https://github.com/excon/excon/pull/901"},{"url":"https://github.com/excon/excon/security/advisories/GHSA-48rx-c7pg-q66r"},{"url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/excon/CVE-2026-54171.yml"},{"url":"https://github.com/advisories/GHSA-48rx-c7pg-q66r"}],"tags":["csaf","vex","red-hat","ghsa","rubygems"],"epss":0.00427,"epssPercentile":0.34245,"aliases":["GHSA-48rx-c7pg-q66r"],"ecosystem":"rubygems","ingestedAt":"2026-07-10T21:06:31.243Z","slug":"CVE-2026-54171","body":"## Overview\n\nA flaw was found in Excon, a Ruby HTTP client library. The RedirectFollower middleware, responsible for handling redirects, failed to remove sensitive header information when a request was redirected to a new target. This oversight could lead to the unintended exposure of confidential data to an unauthorized destination, potentially compromising sensitive information.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat 3scale API Management Platform 2, Red Hat Satellite 6 · no fix planned: Red Hat 3scale API Management Platform 2, Red Hat Satellite 6 · updated 2026-09-07 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54171.json)\n\n**excon: Excon: Information disclosure via unstripped sensitive headers during redirects** — rated Moderate by Red Hat. Released 2026-07-17, updated 2026-09-07.\n\nAffected:\n\n- Red Hat 3scale API Management Platform 2\n- Red Hat Satellite 6\n\nNo fix planned:\n\n- Red Hat 3scale API Management Platform 2\n- Red Hat Satellite 6\n\n## Remediation\n\nFix deferred\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-54171)\n\nAffected packages:\n\n- `excon < 1.5.0`\n\nPatched in:\n\n- `excon 1.5.0`\n\nSource: https://github.com/advisories/GHSA-48rx-c7pg-q66r","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}