Junglewise Threat Intelligence

Hubuum hubuum_client sensitive information disclosure in diagnostics

Severity: low · CVSS 2.3 · Published 2026-07-24

Technologies: hubuum_client (crates.io). Vendors: crates.io.

Executive brief

The Hubuum Rust client library, used for interacting with Hubuum services, contains a vulnerability where sensitive information may be inadvertently written to application logs. This occurs because the library's diagnostic and error-handling features do not automatically strip secrets like credentials, tokens, and private data from error messages or request summaries. If an application logs these errors, an unauthorized person with access to the logs could view sensitive business data or authentication tokens.

Technical details

The hubuum_client library (Rust) is vulnerable to sensitive information disclosure (CWE-532) via its diagnostic implementations. Native reqwest::Error values and internal ApiError variants (such as Http and RetryExhausted) preserve full request URLs including query parameters, which may contain secrets. Additionally, several public models and response types implement diagnostic traits that include raw response bodies, cursors, export payloads, and event-delivery claims. An attacker with access to application logs or diagnostic output can recover sensitive tokens, credentials, and internal object data. The vulnerability is addressed in version 0.6.1 by implementing redaction for query values and sanitizing default error/model diagnostics to report metadata instead of raw payloads.

Affected products

  • hubuum hubuum_client <= 0.6.0

Timeline

  • 2026-07-23: disclosed: Advisory published by maintainer
  • 2026-07-23: patched: Version 0.6.1 released

References

Related threats