THREAT OPS › Threat News › [GHSA] GHSA-486v-q2wf-fp2r (low) — rclone: http backend forwards custom/auth headers to a different host on redirect
[GHSA] GHSA-486v-q2wf-fp2r (low) — rclone: http backend forwards custom/auth headers to a different host on redirect
GHSA-486v-q2wf-fp2r Severity: low CVE: CVE-2026-88013
rclone: http backend forwards custom/auth headers to a different host on redirect
## Vulnerability Details
**File**: `backend/http/http.go` **Lines**: 285 (client construction — no `CheckRedirect`), 505-510 (`addHeaders`, writes configured secret headers onto every request), 533-534 / 700-701 / 782-785 (`f.httpClient.Do(req)` used by List/st
Indicators of compromise
- CVE-2026-88013cve
- https://`url
- http://`url
- http://127.0.0.1:9090/url
- http://127.0.0.1:9090/file.txturl
Original source: https://github.com/advisories/GHSA-486v-q2wf-fp2r