Junglewise Threat Intelligence

CVE-2026-48595: Elixir Tesla credential leakage in FollowRedirects middleware

CVE-2026-48595 · Severity: high · CVSS 8.2 · Published 2026-06-02

Technologies: Elixir-Tesla Tesla.

Executive brief

Tesla, a popular HTTP client library for Elixir, contains a flaw where sensitive login credentials (like bearer tokens) can be accidentally sent to untrusted websites. When the library follows a link that redirects to a different website, it is supposed to remove security headers, but it fails to do so if the header name uses standard capitalization (e.g., 'Authorization' instead of 'authorization'). This could allow an attacker to steal user credentials by redirecting a victim's request to a server they control.

Technical details

The `Tesla.Middleware.FollowRedirects` component performs case-sensitive filtering against a lowercase list of sensitive headers (`["authorization", "host"]`). Because Tesla preserves the original casing of headers provided by the caller, a header defined as `"Authorization"` (canonical casing) bypasses the `k not in @filter_headers` check. An attacker who controls a redirect destination (via a 3xx response) can capture these forwarded credentials. The vulnerability is present in versions 0.6.0 through 1.18.2 and is fixed in 1.18.3 by implementing case-insensitive header comparison.

Affected products

  • elixir-tesla tesla >= 0.6.0, < 1.18.3

Timeline

  • 2026-06-02: disclosed: Initial disclosure and NVD publication
  • 2026-07-10: advisory: GitHub Advisory published
  • 1.18.3: patched

References