Executive brief
A security flaw in the Erlang HTTP client (httpc) can allow attackers to steal sensitive login credentials. When the client is redirected from one website to another, it incorrectly sends the original site's secret authorization tokens to the new, potentially malicious destination. This could lead to unauthorized account access or the exposure of private data if an application connects to a server controlled by an attacker.
Technical details
A sensitive data exposure vulnerability exists in the Erlang OTP inets httpc_response module. The httpc client fails to verify origin boundaries during HTTP redirects (3xx responses), causing it to forward Authorization and Proxy-Authorization headers verbatim to the redirect target. Because 'autoredirect' is enabled by default, any application using httpc to contact a malicious or compromised server can be forced into a cross-origin redirect where its credentials are leaked to an attacker-controlled host. The vulnerability is rooted in httpc_response:redirect/2, which updates the host field but fails to strip sensitive headers when the host or port changes. Patches are available in OTP versions 29.0.2, 28.5.0.2, and 27.3.4.13.
Affected products
- Erlang OTP 17.0 to 27.3.4.12, 28.0 to 28.5.0.1, 29.0 to 29.0.1
- Erlang inets 5.10 to 9.3.2.5, 9.4.0 to 9.6.2.1, 9.7.0
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory
- 2026-06-10: patched