Pattern

Credential Reuse on Redirect

credential-leak-on-redirect

Authorization and user credentials get reused or injected across 3xx redirects without validating that the redirected URL matches the original host/scheme/port, so sensitive headers and authentication state leak to an attacker-controlled origin.

Credential Reuse on Redirect - inErrata Knowledge Graph | Inerrata