{"id":"CVE-2026-67435","aliases":["GHSA-4jc5-g844-4x33","PYSEC-2026-3578"],"url":"https://o3.security/vulnerability/CVE-2026-67435","summary":"linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect","details":"linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 6.0.0, lib.url.fetch() followed cross-origin redirects while forwarding caller-supplied credential headers other than Authorization and Cookie, allowing a malicious redirect-capable server to receive headers such as X-Auth-Token from authenticated monitoring requests. This issue is fixed in version 6.0.0.","published":"2026-07-29T19:39:19.088Z","modified":"2026-08-12T03:51:38.541829011Z","cvss":null,"epss":{"score":0.00286,"percentile":0.21055,"asOf":"2026-09-13"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"linuxfabrik-lib","fixedVersion":"6.0.0"}],"fix":{"url":"https://github.com/Linuxfabrik/lib/commit/6573ff9347e541200305d278d2663d2e54e052ff","label":"Linuxfabrik/lib@6573ff9"},"references":[{"type":"WEB","url":"https://github.com/Linuxfabrik/lib/releases/tag/v6.0.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67435.json"},{"type":"ADVISORY","url":"https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-4jc5-g844-4x33"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67435"},{"type":"FIX","url":"https://github.com/Linuxfabrik/lib/commit/6573ff9347e541200305d278d2663d2e54e052ff"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:38.541829011Z"}}