Authorization and Cookie headers set via --header leak to a different host on cross-host redirect#5310 · closed · 0 comments