Advisory Database
  • Advisories
  • Dependency Scanning
  1. gem
  2. ›
  3. excon
  4. ›
  5. CVE-2026-54171

CVE-2026-54171: Excon does not redact additional sensitive/risky headers when following redirects

July 10, 2026 (updated July 21, 2026)

The redirect follower middleware previously failed to strip a number of headers that are known to be sensitive and did not provide a way to provide a custom list of headers to strip.

What kind of vulnerability is it? Who is impacted? This could cause inadvertent leakage of sensitive data for users of the RedirectFollower middleware in cases where the initial request includes header information that is not intended for the new target.

References

  • github.com/advisories/GHSA-48rx-c7pg-q66r
  • github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3
  • github.com/excon/excon/pull/901
  • github.com/excon/excon/security/advisories/GHSA-48rx-c7pg-q66r
  • github.com/rubysec/ruby-advisory-db/blob/master/gems/excon/CVE-2026-54171.yml
  • nvd.nist.gov/vuln/detail/CVE-2026-54171
  • www.cve.org/CVERecord?id=CVE-2026-54171

Code Behaviors & Features

Detect and mitigate CVE-2026-54171 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.5.0

Fixed versions

  • 1.5.0

Solution

Upgrade to version 1.5.0 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-201: Insertion of Sensitive Information Into Sent Data
  • CWE-522: Insufficiently Protected Credentials

Source file

gem/excon/CVE-2026-54171.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:19:21 +0000.