THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8mxv-9xhp-86h4 (medium) — rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

[GHSA] GHSA-8mxv-9xhp-86h4 (medium) — rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

medgithub_advisoriesPublished 2026-08-05

GHSA-8mxv-9xhp-86h4 Severity: medium CVE: None

rclone: S3 Redirect Sanitization Omits IBM IAM Bearer Tokens and SSE-C Keys

## 1. Summary

The S3 redirect callback strips `X-Amz-Security-Token` when a redirect changes scheme or host, but it does not strip IBM IAM bearer authorization or customer-provided encryption keys. Two independently validated paths remain:

- a same-host HTTPS-to-HTTP redir

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-8mxv-9xhp-86h4