CVE-2026-67435: Linuxfabrik Monitoring-Plugins
Medium severity, CVSS 6.0. EPSS: 0.5% chance of exploitation in the next 30 days.
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 6.0.0, lib.url.fetch() followed cross-origin redirects while forwarding caller-supplied credential headers other than Authorization and Cookie, allowing a malicious redirect-capable server to receive headers such as X-Auth-Token from authenticated monitoring requests. This issue is fixed in version 6.0.0.
Affected products
- Linuxfabrik Monitoring-Plugins: before 6.0.0 (fixed in 6.0.0)
Published 2026-07-29. Last modified 2026-07-30.