> USN-8632-1: follow-redirects vulnerability
[DATE: 12/08/2026 20:27]
[LANGUAGE: EN]
Dennis Sepede discovered that follow-redirects did not properly remove
custom authentication headers when following cross-domain redirects. An
attacker could possibly use this issue to obtain sensitive authentication
information, resulting in credential disclosure.