THREAT OPS › Threat News › [GHSA] GHSA-9g45-5xwm-f3wc (medium) — RMCP: Custom HTTP headers leak to cross-origin redirect targets
[GHSA] GHSA-9g45-5xwm-f3wc (medium) — RMCP: Custom HTTP headers leak to cross-origin redirect targets
GHSA-9g45-5xwm-f3wc Severity: medium CVE: CVE-2026-64684
RMCP: Custom HTTP headers leak to cross-origin redirect targets
## Summary
The `rmcp` crate's `StreamableHttpClientTransport` forwards caller-supplied custom HTTP headers (such as `X-API-Key`, `X-Auth-Token`, `Api-Key`) to cross-origin redirect targets. The `default_http_client()` function builds a `reqwest::Client` without a redirect pol
Indicators of compromise
- c330fede90e4729c234f8e87fdbc5ea27a1dd10csha1
- CVE-2026-64684cve
Original source: https://github.com/advisories/GHSA-9g45-5xwm-f3wc