THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-v25g-mvwr-f5fp (medium) — webhookd: Unrestricted HTTP Header to Shell Variable Injection

[GHSA] GHSA-v25g-mvwr-f5fp (medium) — webhookd: Unrestricted HTTP Header to Shell Variable Injection

medgithub_advisoriesPublished 2026-09-09

GHSA-v25g-mvwr-f5fp Severity: medium CVE: CVE-2026-59157

webhookd: Unrestricted HTTP Header to Shell Variable Injection

## Description Before 1.22, if the Basic Auth (`htpasswd`) middleware was not configured, all incoming HTTP headers were blindly forwarded to the webhook script execution environment as shell variables. While the Basic Auth middleware correctly strips the authentication header

Indicators of compromise

Original source: https://github.com/advisories/GHSA-v25g-mvwr-f5fp