Intel

AIKIDO-2026-571839

dio_http2_adapter is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized ActorGHSA-cr65-55v9-xhvv Published Aug 20, 2026

75

High Risk

This Affects:

DARTdio_http2_adapter
1.0.0 - 2.7.1
Fixed in 2.8.0
Are you affected? Scan for Free

TL;DR

The HTTP/2 adapter for the dio client copies all original request headers onto the follow-up request when it handles a redirect response. Because it does not compare the redirect target origin against the original origin, sensitive headers such as authorization, cookie, and proxy-authorization are forwarded to a different host. A redirect response from an untrusted server can therefore cause authentication credentials to be disclosed to that host. The fix strips these sensitive headers when a redirect crosses an origin boundary.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your application sends requests carrying sensitive headers such as authorization or cookie while following redirects.

Background info

dio_http2_adapter is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.0.0 - 2.7.1.

How to fix this

Upgrade the dio_http2_adapter library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform