OSV 1.4.0 · github-reviewed · 修改于 2026-06-16 04:20
发布时间
2026-06-16 04:20
GitHub 审查时间
2026-06-16 04:20
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/06/GHSA-3x9g-8vmp-wqvf/GHSA-3x9g-8vmp-wqvf.json
When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin.
As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default.
Beginning in Tornado 6.5.6, SimpleAsyncHTTPClient matches the default behavior of libcurl (and therefore CurlAsyncHTTPClient): When a redirect changes the scheme, host, or port of the url, the Authorization and Cookie headers will be removed when following the redirect.