PT-2026-65902 · Unknown · Linuxfabrik-Lib

CVE-2026-67435

·

Published

2026-07-29

·

Updated

2026-08-04

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions linuxfabrik-lib versions prior to 6.0.0
Description The lib.url.fetch() function follows cross-origin redirects while forwarding caller-supplied credential headers, excluding Authorization and Cookie. This behavior allows a malicious server capable of redirects to capture sensitive headers, such as X-Auth-Token, during authenticated monitoring requests.
Recommendations Update to version 6.0.0.

Exploit

Fix

Information Disclosure

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67435
GHSA-4JC5-G844-4X33
PYSEC-2026-3578

Affected Products

Linuxfabrik-Lib