Skip to content

[GHSA-cmxv-58fp-fm3g] AsyncHttpClient leaks authorization credentialsto untrusted domains on cross-origin redirects#7493

Open
hyperxpro wants to merge 1 commit intohyperxpro/advisory-improvement-7493from
hyperxpro-GHSA-cmxv-58fp-fm3g
Open

[GHSA-cmxv-58fp-fm3g] AsyncHttpClient leaks authorization credentialsto untrusted domains on cross-origin redirects#7493
hyperxpro wants to merge 1 commit intohyperxpro/advisory-improvement-7493from
hyperxpro-GHSA-cmxv-58fp-fm3g

Conversation

@hyperxpro
Copy link
Copy Markdown

Updates

  • Affected products
  • Description

Comments
Vulnerability fix was backported to 2.x release line in 2.14.5 release.

@github
Copy link
Copy Markdown
Collaborator

github commented Apr 23, 2026

Hi there @hyperxpro! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

Copilot AI review requested due to automatic review settings April 23, 2026 20:33
@github-actions github-actions Bot changed the base branch from main to hyperxpro/advisory-improvement-7493 April 23, 2026 20:34
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the GitHub-reviewed advisory for GHSA-cmxv-58fp-fm3g to reflect the backported fix on the 2.x release line and to refine affected version ranges for AsyncHttpClient.

Changes:

  • Update advisory details to note fixes in both 3.0.9 (3.x) and 2.14.5 (2.x).
  • Refine the affected-version range for the 3.x line and add a new affected range for the 2.x line.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

"aliases": [
"CVE-2026-40490"
],
"summary": "AsyncHttpClient leaks authorization credentialsto untrusted domains on cross-origin redirects",
Copy link

Copilot AI Apr 23, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The summary contains a typo: "credentialsto" is missing a space. Consider updating it to "credentials to" for readability/searchability.

Suggested change
"summary": "AsyncHttpClient leaks authorization credentialsto untrusted domains on cross-origin redirects",
"summary": "AsyncHttpClient leaks authorization credentials to untrusted domains on cross-origin redirects",

Copilot uses AI. Check for mistakes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants