Executive brief
The Hubuum Rust client library contains a flaw where sensitive login credentials (authentication headers) can be accidentally sent to unintended locations on the same server. If a server or an attacker can trigger a redirect, the library may follow that redirect and include the user's private security token in the new request. This could allow an unauthorized party to capture credentials if they control a different application hosted on the same domain.
Technical details
The Hubuum Rust client library (hubuum_client) utilizes the reqwest HTTP library with its default redirect policy. While the library's BaseUrl configuration constrains the initial request, reqwest's default behavior retains sensitive headers (like the bearer Authorization header) when a redirect occurs within the same scheme, host, and port. An attacker or a compromised server capable of influencing a 3xx redirect response can redirect a client request to a different path on the same origin, causing the client to leak the authentication token to that path. This is classified as CWE-200 (Exposure of Sensitive Information). The issue is fixed in version 0.6.1 by disabling automatic redirects in the built-in HTTP clients.
Affected products
- Hubuum hubuum_client >= 0.0.1, < 0.6.1
Timeline
- 2026-07-23: disclosed
- 2026-07-24: advisory
- 2026-07-24: patched: Fixed in version 0.6.1