THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-486v-q2wf-fp2r (low) — rclone: http backend forwards custom/auth headers to a different host on redirect

[GHSA] GHSA-486v-q2wf-fp2r (low) — rclone: http backend forwards custom/auth headers to a different host on redirect

highgithub_advisoriesPublished 2026-09-10

GHSA-486v-q2wf-fp2r Severity: low CVE: CVE-2026-88013

rclone: http backend forwards custom/auth headers to a different host on redirect

## Vulnerability Details

**File**: `backend/http/http.go` **Lines**: 285 (client construction — no `CheckRedirect`), 505-510 (`addHeaders`, writes configured secret headers onto every request), 533-534 / 700-701 / 782-785 (`f.httpClient.Do(req)` used by List/st

Indicators of compromise

Original source: https://github.com/advisories/GHSA-486v-q2wf-fp2r