From 2215f1b988dd544f186b9ae05d0a7061bf92b80f Mon Sep 17 00:00:00 2001 From: neil Date: Sat, 11 Jul 2026 11:56:58 +0800 Subject: [PATCH] notify: clear inherited _H1.._H5 before running each notify hook The dns/deploy hooks export _H1.._H5 in the main process, and the notify hooks run in a subshell that inherits them. A hook that does not overwrite every slot (ntfy without NTFY_TOKEN, slack, telegram, etc.) sent the stale headers with its request, leaking another service's Authorization credentials to the notify endpoint. https://github.com/acmesh-official/acme.sh/issues/6801 --- acme.sh | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/acme.sh b/acme.sh index 6495a90e..9ec92585 100755 --- a/acme.sh +++ b/acme.sh @@ -7765,6 +7765,14 @@ _send_notify() { continue fi if ! ( + # The dns/deploy hooks export _H1.._H5 in the main process, so the + # values are inherited here. Clear them: a stale Authorization header + # from another service must not leak into the notify request. + export _H1="" + export _H2="" + export _H3="" + export _H4="" + export _H5="" if ! . "$_n_hook_file"; then _err "Error loading file $_n_hook_file. Please check your API file and try again." return 1