MEDIUMGo
GHSA-h5gx-45rj-2h5j· CVE-2026-50192, GO-2026-5890Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirect
Modified: 7/7/2026
package
pkg:go/github.com/kerberos-io/agent/machinery
Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirect
Modified: 7/7/2026
Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirect in github.com/kerberos-io/agent/machinery
Modified: 7/7/2026