VDB

CVE-2026-59180

CVE-2026-59180 PUBLISHED CVSS 3.1 LOW

Reported by GitHub_M · Published July 10, 2026

Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and config loaders in apprise/attachment/http.py and apprise/config/http.py follow HTTP redirects by default and resend user-configured auth headers and query parameters on the redirected request, allowing a compromised trusted destination or on-path attacker to receive secrets such as Authorization headers, bearer tokens, custom headers, and service keys. This issue is fixed in version 1.11.0.

Risk Scores

CVSS 3.1
3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
caroncapprise< 1.11.0
caroncapprise< 1.11.0

Timeline

  • Jul 10, 2026 Coalition ESS Score
  • Jul 10, 2026 CVE Published
  • Jul 10, 2026 CVE Updated
  • Jul 12, 2026 EPSS Score
  • Jul 13, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 27, 2026 EPSS Score
  • Sep 2, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›