Undici already cleared Authorization headers on cross-origin redirects, but did not clear Proxy-Authorization headers.
Proxy-Authorization
This is patched in v5.28.3 and v6.6.1
There are no known workarounds.
{ "last_known_affected_version_range": "<= 5.28.2" }
{ "last_known_affected_version_range": "<= 6.6.0" }