Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0.
References
| Link | Resource |
|---|---|
| https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3 | Patch |
| https://github.com/excon/excon/pull/901 | Issue Tracking Patch |
| https://github.com/excon/excon/security/advisories/GHSA-48rx-c7pg-q66r | Patch Vendor Advisory |
Configurations
History
29 Jul 2026, 15:20
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:excon_project:excon:*:*:*:*:*:ruby:*:* | |
| First Time |
Excon Project excon
Excon Project |
|
| References | () https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3 - Patch | |
| References | () https://github.com/excon/excon/pull/901 - Issue Tracking, Patch | |
| References | () https://github.com/excon/excon/security/advisories/GHSA-48rx-c7pg-q66r - Patch, Vendor Advisory |
17 Jul 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-17 20:17
Updated : 2026-07-29 15:20
NVD link : CVE-2026-54171
Mitre link : CVE-2026-54171
CVE.ORG link : CVE-2026-54171
JSON object : View
Products Affected
excon_project
- excon
CWE
CWE-201
Insertion of Sensitive Information Into Sent Data
