Dennis Sepede discovered that follow-redirects did not properly remove custom authentication headers when following cross-domain redirects. An attacker could possibly use this issue to obtain sensitive authentication information, resulting in credential disclosure.
USN-8632-1: follow-redirects vulnerability
calendar_today
August 12, 2026
domain
ubuntu