Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-54171

Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 24.1%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-54171


Contact Us

Shodan ® - All rights reserved