{"id":"GHSA-f45q-w629-wr25","aliases":[],"url":"https://o3.security/vulnerability/GHSA-f45q-w629-wr25","summary":"Hubuum client library (Rust): Authenticated requests may escape the configured base path through redirects","details":"## Impact\n\nThe built-in async and blocking clients used reqwest's default redirect policy. `BaseUrl` constrains the initial request to the configured origin and path prefix, but redirect processing occurs after that validation. reqwest retains sensitive headers when a redirect changes only the path on the same scheme, host, and port. A redirect from a Hubuum endpoint to another path on a shared origin could therefore carry the bearer `Authorization` header outside the configured Hubuum path prefix.\n\nExploitation requires an attacker, compromised server, or intermediary to influence a 3xx response. Cross-origin redirects are not affected because reqwest strips sensitive headers when scheme, host, or port changes.\n\n## Patches\n\nVersion 0.6.1 configures both built-in HTTP clients with `reqwest::redirect::Policy::none()`. Redirect responses are returned as 3xx API errors instead of being followed. Supplying a preconfigured reqwest client remains an explicit opt-in to that client's redirect policy.\n\n## Workarounds\n\nOn affected versions, construct a reqwest client with `reqwest::redirect::Policy::none()` and pass it through `with_http_client`. Deployments can also reduce exposure by ensuring the Hubuum origin is not shared with other applications and that trusted infrastructure never redirects API requests outside the configured path prefix.","published":"2026-07-24T21:48:36Z","modified":"2026-07-24T22:00:26.904951923Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"hubuum_client","fixedVersion":"0.6.1"}],"fix":{"url":"https://github.com/hubuum/hubuum-client-rust/commit/5a5c275ffa45f342459b7d3e977926da643bde50","label":"hubuum/hubuum-client-rust@5a5c275"},"references":[{"type":"WEB","url":"https://github.com/hubuum/hubuum-client-rust/security/advisories/GHSA-f45q-w629-wr25"},{"type":"WEB","url":"https://github.com/hubuum/hubuum-client-rust/commit/5a5c275ffa45f342459b7d3e977926da643bde50"},{"type":"PACKAGE","url":"https://github.com/hubuum/hubuum-client-rust"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-24T22:00:26.904951923Z"}}