« Volver al listado

CVE-2026-48856

Estado: ModificadaAlta (7.1)—

Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data.

The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking whether the redirect crosses an origin boundary. httpc_response:redirect/2 constructs the redirected request by updating only the host field of the header record; all other fields (including authorization and proxy_authorization) are copied verbatim. The redirect target host is never compared against the original host.

autoredirect defaults to true, so this affects all httpc callers that do not explicitly disable automatic redirects.

Leer descripción completaMostrar menos

An attacker who controls a server that the victim contacts via httpc can issue a cross-origin 3xx redirect to a server they also control. The Authorization header (including Basic credentials derived from URL userinfo via httpc_request:handle_user_info/2) is forwarded to the redirect target, allowing credential theft. The same applies to the Proxy-Authorization header.

This vulnerability is associated with program files lib/inets/src/http_client/httpc_response.erl.

This issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to inets from 5.10 before 9.3.2.6, 9.6.2.2, and 9.7.1. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CVE-2026-48856: Requiere interacción del usuario (UI:P) para hacer clic en un enlace que redirige; httpc cliente expuesto a robo de credenciales en redirects cross-origin sin validación de destino.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-48856",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-48856",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-10T16:23:52.053802Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 7.1,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "PASSIVE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
          ],
          "vendor": "Erlang",
          "modules": [
            "httpc_response"
          ],
          "product": "OTP",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "27.3.4.13",
                  "status": "unaffected"
                },
                {
                  "at": "28.5.0.2",
                  "status": "unaffected"
                },
                {
                  "at": "29.0.2",
                  "status": "unaffected"
                }
              ],
              "version": "17.0",
              "lessThan": "*",
              "versionType": "otp"
            }
          ],
          "packageURL": "pkg:software-id/erlang.org/otp",
          "packageName": "otp",
          "programFiles": [
            "lib/inets/src/http_client/httpc_response.erl"
          ],
          "defaultStatus": "unknown",
          "programRoutines": [
            {
              "name": "httpc_response:redirect/2"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/erlang/otp",
          "vendor": "Erlang",
          "modules": [
            "httpc_response"
          ],
          "product": "OTP",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "9.3.2.6",
                  "status": "unaffected"
                },
                {
                  "at": "9.6.2.2",
                  "status": "unaffected"
                },
                {
                  "at": "9.7.1",
                  "status": "unaffected"
                }
              ],
              "version": "5.10",
              "lessThan": "*",
              "versionType": "otp"
            }
          ],
          "packageURL": "pkg:otp/inets?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
          "packageName": "inets",
          "programFiles": [
            "src/http_client/httpc_response.erl"
          ],
          "defaultStatus": "unknown",
          "programRoutines": [
            {
              "name": "httpc_response:redirect/2"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/erlang/otp",
          "vendor": "Erlang",
          "modules": [
            "httpc_response"
          ],
          "product": "OTP",
          "versions": [
            {
              "status": "affected",
              "version": "84adefa331c4159d432d22840663c38f155cd4c1",
              "lessThan": "688d748d6f7a6a06b13b662a1d3de8af97079612",
              "versionType": "git"
            },
            {
              "status": "unaffected",
              "version": "688d748d6f7a6a06b13b662a1d3de8af97079612",
              "lessThan": "*",
              "versionType": "git"
            }
          ],
          "packageURL": "pkg:github/erlang/otp",
          "packageName": "erlang/otp",
          "programFiles": [
            "lib/inets/src/http_client/httpc_response.erl"
          ],
          "collectionURL": "https://github.com",
          "defaultStatus": "unknown",
          "programRoutines": [
            {
              "name": "httpc_response:redirect/2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-10T16:17:10.053",
  "references": [
    {
      "url": "https://cna.erlef.org/cves/CVE-2026-48856.html",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/erlang/otp/commit/688d748d6f7a6a06b13b662a1d3de8af97079612",
      "tags": [
        "Patch"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/erlang/otp/security/advisories/GHSA-m75x-4vwg-ggjh",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://osv.dev/vulnerability/EEF-CVE-2026-48856",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
      "tags": [
        "Product"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data.\n\nThe httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking whether the redirect crosses an origin boundary. httpc_response:redirect/2 constructs the redirected request by updating only the host field of the header record; all other fields (including authorization and proxy_authorization) are copied verbatim. The redirect target host is never compared against the original host.\n\nautoredirect defaults to true, so this affects all httpc callers that do not explicitly disable automatic redirects.\n\nAn attacker who controls a server that the victim contacts via httpc can issue a cross-origin 3xx redirect to a server they also control. The Authorization header (including Basic credentials derived from URL userinfo via httpc_request:handle_user_info/2) is forwarded to the redirect target, allowing credential theft. The same applies to the Proxy-Authorization header.\n\nThis vulnerability is associated with program files lib/inets/src/http_client/httpc_response.erl.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to inets from 5.10 before 9.3.2.6, 9.6.2.2, and 9.7.1. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown."
    }
  ],
  "lastModified": "2026-09-24T21:17:14.390",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:erlang:erlang\\/inets:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B10D06D-6CAA-4AE6-9971-9D21A7347468",
              "versionEndExcluding": "9.3.2.6",
              "versionStartIncluding": "5.10"
            },
            {
              "criteria": "cpe:2.3:a:erlang:erlang\\/inets:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FF460097-653F-4CA0-8FF7-1F674F6D956E",
              "versionEndExcluding": "9.6.2.2",
              "versionStartIncluding": "9.6"
            },
            {
              "criteria": "cpe:2.3:a:erlang:erlang\\/inets:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85B29B67-5B41-4987-A71F-A7A0458E49E4",
              "versionEndExcluding": "9.7.1",
              "versionStartIncluding": "9.7"
            },
            {
              "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
              "versionEndExcluding": "27.3.4.13",
              "versionStartIncluding": "17.0"
            },
            {
              "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
              "versionEndExcluding": "28.5.0.2",
              "versionStartIncluding": "28.0"
            },
            {
              "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
              "versionEndExcluding": "29.0.2",
              "versionStartIncluding": "29.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}