{"id":"CVE-2026-50192","aliases":["GHSA-h5gx-45rj-2h5j","GO-2026-5890"],"url":"https://o3.security/vulnerability/CVE-2026-50192","summary":"Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirect","details":"Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` request headers to the operator-configured Hub URL (`config.HubURI`). The HTTP client used (`&http.Client{}` in `UploadKerberosHub`) is constructed without a `CheckRedirect` policy, so it follows HTTP redirects automatically. Go's `net/http` strips only sensitive headers (`Authorization`, `Cookie`, `WWW-Authenticate`) on a cross-host redirect; it does not strip custom headers such as `X-Kerberos-Hub-PrivateKey`. As a result, if the configured `HubURI` returns a cross-host 30x redirect, the Hub private key is forwarded verbatim to the redirect target, disclosing the credential to an unintended third party. Version 3.6.26 fixes the issue by implementing the `CheckRedirect` strip plus a cross-host regression test is provided to the maintainer through the advisory's private temporary fork.","published":"2026-08-20T21:37:20.598Z","modified":"2026-08-23T03:42:58.321728781Z","cvss":null,"epss":{"score":0.00249,"percentile":0.1614,"asOf":"2026-09-08"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/kerberos-io/agent/machinery","fixedVersion":"0.0.0-20260528173546-51f1a52e170f"}],"fix":{"url":"https://github.com/kerberos-io/agent/commit/51f1a52e170f21c1264c6de1dc781d5b5e2a5d09","label":"kerberos-io/agent@51f1a52"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50192.json"},{"type":"ADVISORY","url":"https://github.com/kerberos-io/agent/security/advisories/GHSA-h5gx-45rj-2h5j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50192"},{"type":"FIX","url":"https://github.com/kerberos-io/agent/commit/51f1a52e170f21c1264c6de1dc781d5b5e2a5d09"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-23T03:42:58.321728781Z"}}