WebDAV's default redirect handling can replay Basic authorization and configured Cookie headers over plaintext HTTP after a same-host HTTPS-to-HTTP redirect. This was reproduced through the real backend. Unlike the low-impact STS token in rclone's published S3 redirect advisory, Basic passwords and session cookies are complete reusable credentials, supporting a High rating when they grant normal WebDAV read/write access.
The credible threat requires a legitimate endpoint, gateway, or accelerator to emit an unsafe redirect and an adjacent/on-path actor to observe the plaintext hop. A report should not rely on a malicious original WebDAV endpoint because that endpoint already receives the credentials.
backend/webdav/webdav.go:127-139, 170-206, 440-530lib/rest/rest.go:218-231fs/fshttp/http.go:311-329<= v1.74.0-240PreserveMethodRedirectFn limits redirect count and restores the original method, but it does not reject a transport downgrade or compare the full origin tuple. The client therefore relies on Go's hostname-oriented sensitive-header forwarding rules. Those rules can preserve Authorization and Cookie on a same-host redirect even when the new scheme is plaintext HTTP.
307 Temporary Redirect to an HTTP listener on the same hostname and a different port.Authorization value and Cookie.An on-path observer can reuse the captured password, bearer token, or session cookie for the account's permitted WebDAV operations. Confidentiality, integrity, and availability impact depend on that account's permissions.
301, 302, 303, 307, and 308 in regression tests.{
"github_reviewed": true,
"nvd_published_at": null,
"cwe_ids": [
"CWE-319",
"CWE-522"
],
"github_reviewed_at": "2026-08-05T20:36:10Z",
"severity": "MODERATE"
}