CVE-2026-48595
Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middleware.FollowRedirects
Description
Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin redirects using a case-sensitive string comparison against a lowercase filter list (@filter_headers ["authorization", "host"]). HTTP header names are case-insensitive per RFC 7230, but Tesla preserves header keys verbatim as supplied by the caller without normalizing case. A header set as {"Authorization", "Bearer …"} (the RFC 7235 canonical casing used by virtually all HTTP libraries and documentation) does not match the lowercase filter entry and is forwarded to the redirect destination. An attacker who can control or influence a Location: response seen by the client (via their own endpoint, a redirect-open upstream, or a compromised origin) receives the bearer token or other Authorization material on the cross-origin request. This issue affects tesla: from 1.4.0 before 1.18.3.
INFO
Published Date :
June 2, 2026, 8:16 p.m.
Last Modified :
July 22, 2026, 7:10 p.m.
Remotely Exploit :
Yes !
Source :
6b3ad84c-e1a6-4bf7-a703-f496b71e49db
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 4.0 | HIGH | 6b3ad84c-e1a6-4bf7-a703-f496b71e49db | ||||
| CVSS 4.0 | HIGH | 6b3ad84c-e1a6-4bf7-a703-f496b71e49db |
Solution
- Update elixir-tesla to version 1.18.3 or later.
- Ensure security-sensitive headers are properly filtered.
Public PoC/Exploit Available at Github
CVE-2026-48595 has a 2 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-48595.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-48595 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-48595
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
None
None
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-48595 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-48595 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Jul. 22, 2026
Action Type Old Value New Value Added Translation Title: tesla de elixir-tesla, Description: Vulnerabilidad de manejo inadecuado de la distinción entre mayúsculas y minúsculas en elixir-tesla tesla permite la fuga de credenciales a un origen de terceros en redirecciones de origen cruzado. Tesla.Middleware.FollowRedirects elimina encabezados sensibles a la seguridad en redirecciones de origen cruzado utilizando una comparación de cadenas que distingue entre mayúsculas y minúsculas contra una lista de filtros en minúsculas (@filter_headers ['authorization', 'host']). Los nombres de los encabezados HTTP no distinguen entre mayúsculas y minúsculas según la RFC 7230, pero Tesla conserva las claves de los encabezados textualmente tal como las proporciona el llamador sin normalizar las mayúsculas y minúsculas. Un encabezado establecido como {'Authorization', 'Bearer ...'} (la capitalización canónica de la RFC 7235 utilizada por prácticamente todas las bibliotecas y documentación HTTP) no coincide con la entrada del filtro en minúsculas y se reenvía al destino de la redirección. Un atacante que puede controlar o influir en una respuesta Location: vista por el cliente (a través de su propio punto final, un upstream de redirección abierta o un origen comprometido) recibe el token de portador u otro material de autorización en la solicitud de origen cruzado. Este problema afecta a tesla: desde 1.4.0 antes de 1.18.3. -
CVE Modified by 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'cpes': ['cpe:2.3:a:elixir-tesla:tesla:*:*:*:*:*:*:*:*'], 'repo': 'https://github.com/elixir-tesla/tesla', 'vendor': 'elixir-tesla', 'modules': ["'Elixir.Tesla.Middleware.FollowRedirects'"], 'product': 'tesla', 'versions': [{'status': 'affected', 'version': '1.4.0', 'lessThan': '1.18.3', 'versionType': 'semver'}], 'packageURL': 'pkg:hex/tesla', 'packageName': 'tesla', 'programFiles': ['lib/tesla/middleware/follow_redirects.ex'], 'collectionURL': 'https://repo.hex.pm', 'defaultStatus': 'unaffected', 'programRoutines': [{'name': "'Elixir.Tesla.Middleware.FollowRedirects':call/3"}]}, {'cpes': ['cpe:2.3:a:elixir-tesla:tesla:*:*:*:*:*:*:*:*'], 'repo': 'https://github.com/elixir-tesla/tesla.git', 'vendor': 'elixir-tesla', 'modules': ["'Elixir.Tesla.Middleware.FollowRedirects'"], 'product': 'tesla', 'versions': [{'status': 'affected', 'version': '2d937d5813d7cda5cd726f41824985fb655c920f', 'lessThan': 'db963dba67651b9abd1fc420a1d9679cf6efe182', 'versionType': 'git'}], 'packageURL': 'pkg:github/elixir-tesla/tesla', 'packageName': 'elixir-tesla/tesla', 'programFiles': ['lib/tesla/middleware/follow_redirects.ex'], 'collectionURL': 'https://github.com', 'defaultStatus': 'unaffected', 'programRoutines': [{'name': "'Elixir.Tesla.Middleware.FollowRedirects':call/3"}]}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-48595', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'poc'}, {'automatable': 'no'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-06-03T15:59:45.683092Z'} -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 03, 2026
Action Type Old Value New Value Added Reference https://github.com/elixir-tesla/tesla/security/advisories/GHSA-9m9w-gxf7-rh8m -
New CVE Received by 6b3ad84c-e1a6-4bf7-a703-f496b71e49db
Jun. 02, 2026
Action Type Old Value New Value Added Description Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin redirects using a case-sensitive string comparison against a lowercase filter list (@filter_headers ["authorization", "host"]). HTTP header names are case-insensitive per RFC 7230, but Tesla preserves header keys verbatim as supplied by the caller without normalizing case. A header set as {"Authorization", "Bearer …"} (the RFC 7235 canonical casing used by virtually all HTTP libraries and documentation) does not match the lowercase filter entry and is forwarded to the redirect destination. An attacker who can control or influence a Location: response seen by the client (via their own endpoint, a redirect-open upstream, or a compromised origin) receives the bearer token or other Authorization material on the cross-origin request. This issue affects tesla: from 1.4.0 before 1.18.3. Added CVSS V4.0 AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Added CWE CWE-178 Added Reference https://cna.erlef.org/cves/CVE-2026-48595.html Added Reference https://github.com/elixir-tesla/tesla/commit/db963dba67651b9abd1fc420a1d9679cf6efe182 Added Reference https://github.com/elixir-tesla/tesla/security/advisories/GHSA-9m9w-gxf7-rh8m Added Reference https://osv.dev/vulnerability/EEF-CVE-2026-48595