GHSA-q6gh-6v2r-hjv3 is a medium-severity (CVSS 6.8) vulnerability in io.micronaut:micronaut-http-client. A fix is available for io.micronaut:micronaut-http-client — see the affected versions and patch details below.
Micronaut: DefaultHttpClient follows redirects, forwarding Authorization, Cookie, and Proxy-Authorization headers
Real-World Exposure
io.micronaut:micronaut-http-client☕io.micronaut:micronaut-http-client☕io.micronaut:micronaut-http-clientReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.
Description
Impact
DefaultHttpClient follows redirects and forwards Authorization, Cookie, and Proxy-Authorization headers to redirect targets across domain boundaries. The blocklist only filters Host/Connection/TE/CT/CL. Additionally, no maximum redirect count exists, enabling infinite loop DoS. Affected: DefaultHttpClient.java lines 231-245, 1591, 2071
Suggested fix: Strip sensitive headers on cross-domain redirects
Patches
It has been patched for versions:
For Micronaut 5, versions equal or greater than 5.0.1 >= For Micronaut 4, versions equal or greater than 4.10.24 >= For Micronaut 3, versions equal or greater than 3.10.6 >=
Workarounds
No
References
Micronaut 5 Patch: https://github.com/micronaut-projects/micronaut-core/commit/9770328999f490bdfbb9e25addd45bf73d4a173a Micronaut 4 Patch: https://github.com/micronaut-projects/micronaut-core/commit/70cab4b44fbf985faba2846091f2356b5bd70719 Micronaut 3 Patch: https://github.com/micronaut-projects/micronaut-core/commit/64e539736b8168f201d868b02ace50fe14f57418
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| ☕Maven | io.micronaut:micronaut-http-client | ≥ 1.2.8&&< 3.10.6 | 3.10.6io.micronaut:micronaut-http-client:3.10.6 |
| ☕Maven | io.micronaut:micronaut-http-client | ≥ 4.0.0-M1&&< 4.10.24 | 4.10.24io.micronaut:micronaut-http-client:4.10.24 |
| ☕Maven | io.micronaut:micronaut-http-client | ≥ 5.0.0-M1&&< 5.0.1 | 5.0.1io.micronaut:micronaut-http-client:5.0.1 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for io.micronaut:micronaut-http-client, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update io.micronaut:micronaut-http-client to 3.10.6 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-q6gh-6v2r-hjv3 is resolved across your whole dependency graph.
Workarounds
Cap what an attacker can consume: apply request size, rate and timeout limits in front of the affected component, and run it with memory and CPU limits so exhaustion degrades one worker rather than the whole service.
Frequently Asked Questions
Is GHSA-q6gh-6v2r-hjv3 in your dependencies?
Find it across Maven, including transitive dependencies.