๐Ÿ” CVE Alert

CVE-2026-50192

UNKNOWN 0.0

Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirect

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` request headers to the operator-configured Hub URL (`config.HubURI`). The HTTP client used (`&http.Client{}` in `UploadKerberosHub`) is constructed without a `CheckRedirect` policy, so it follows HTTP redirects automatically. Go's `net/http` strips only sensitive headers (`Authorization`, `Cookie`, `WWW-Authenticate`) on a cross-host redirect; it does not strip custom headers such as `X-Kerberos-Hub-PrivateKey`. As a result, if the configured `HubURI` returns a cross-host 30x redirect, the Hub private key is forwarded verbatim to the redirect target, disclosing the credential to an unintended third party. Version 3.6.26 fixes the issue by implementing the `CheckRedirect` strip plus a cross-host regression test is provided to the maintainer through the advisory's private temporary fork.

CWE CWE-200 CWE-522
Vendor kerberos-io
Product agent
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for kerberos-io agent

Be the first to know when new unknown vulnerabilities affecting kerberos-io agent are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

kerberos-io / agent
< 3.6.26

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kerberos-io/agent/security/advisories/GHSA-h5gx-45rj-2h5j github.com: https://github.com/kerberos-io/agent/commit/51f1a52e170f21c1264c6de1dc781d5b5e2a5d09