THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h4mf-4v27-hggj (medium) — rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

[GHSA] GHSA-h4mf-4v27-hggj (medium) — rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

medgithub_advisoriesPublished 2026-08-05

GHSA-h4mf-4v27-hggj Severity: medium CVE: None

rclone: WebDAV Credentials Survive a Same-Host HTTPS-to-HTTP Redirect

## 1. Summary

WebDAV's default redirect handling can replay Basic authorization and configured Cookie headers over plaintext HTTP after a same-host HTTPS-to-HTTP redirect. This was reproduced through the real backend. Unlike the low-impact STS token in rclone's published S3 redir

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-h4mf-4v27-hggj