Vulnerability Description
Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` request headers to the operator-configured Hub URL (`config.HubURI`). The HTTP client used (`&http.Client{}` in `UploadKerberosHub`) is constructed without a `CheckRedirect` policy, so it follows HTTP redirects automatically. Go's `net/http` strips only sensitive headers (`Authorization`, `Cookie`, `WWW-Authenticate`) on a cross-host redirect; it does not strip custom headers such as `X-Kerberos-Hub-PrivateKey`. As a result, if the configured `HubURI` returns a cross-host 30x redirect, the Hub private key is forwarded verbatim to the redirect target, disclosing the credential to an unintended third party. Version 3.6.26 fixes the issue by implementing the `CheckRedirect` strip plus a cross-host regression test is provided to the maintainer through the advisory's private temporary fork.
Related Weaknesses (CWE)
References
- https://github.com/kerberos-io/agent/commit/51f1a52e170f21c1264c6de1dc781d5b5e2a
- https://github.com/kerberos-io/agent/security/advisories/GHSA-h5gx-45rj-2h5j
- https://github.com/kerberos-io/agent/security/advisories/GHSA-h5gx-45rj-2h5j
FAQ
What is CVE-2026-50192?
CVE-2026-50192 is a documented vulnerability. Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey...
How severe is CVE-2026-50192?
CVSS scoring is not yet available for CVE-2026-50192. Check NVD for updates.
Is there a patch for CVE-2026-50192?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.