Skip to content
MediumVulnerability

GHSA-9g45-5xwm-f3wc: RMCP: Custom HTTP headers leak to cross-origin redirect targets

Published
Record updated
View JSON
Affected
  • rmcp < 2.1.0
Fixed in
2.1.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.5%

Summary

The rmcp crate's StreamableHttpClientTransport forwards caller-supplied custom HTTP headers, such as X-API-Key, X-Auth-Token and Api-Key, to cross-origin redirect targets. The default_http_client() function sets no redirect policy override, so reqwest's default limited(10) policy follows 307/308 redirects and strips only Authorization, Cookie and Proxy-Authorization, leaving headers set through StreamableHttpClientTransportConfig.custom_headers intact. An attacker who controls a redirect target can capture those secrets, as tested at commit c330fede90e4729c234f8e87fdbc5ea27a1dd10c.

Mitigation

In default_http_client(), add .redirect(reqwest::redirect::Policy::none()) to the reqwest::Client builder so the transport can inspect 3xx responses and strip sensitive headers before following them. Alternatively, use reqwest::ClientBuilder::connection_verbose or per-request Request::headers_mut() to remove auth headers before the redirect is followed.