Vulnerabilities in follow-redirects
4 resultsVexday analysis
O pacote follow-redirects registra 4 vulnerabilidades catalogadas, nenhuma em exploração ativa no momento, concentrando-se em problemas de exposição de informações (CWE-200). Não há criticidade severa (CVSS crítico) e o risco aparenta ser estável, sem novos registros nos últimos 90 dias, sugerindo que as exposições são de menor urgência operacional.
CVE-2022-0155HIGHExposure of Private Personal Information to an Unauthorized Actor in follow-redirects/follow-redirectsEPSS 2.4%CVE-2022-0536LOWImproper Removal of Sensitive Information Before Storage or Transfer in follow-redirects/follow-redirectsEPSS 1.3%CVE-2024-28849MEDIUMProxy-Authorization header kept across hosts in follow-redirectsEPSS 1.0%CVE-2026-40895MEDIUMfollow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect TargetsEPSS 0.5%