Medium severity5.3GHSA Advisory· Published Jul 17, 2020· Updated Jun 17, 2026
CVE-2020-7696
CVE-2020-7696
Description
This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization: "..." }} is loaded, all other subsequent images will use the same headers, this can lead to signing credentials or other session tokens being leaked to other servers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
react-native-fast-imagenpm | < 8.3.0 | 8.3.0 |
Affected products
3- Range: < 8.3.0
- cpe:2.3:a:react-native-fast-image_project:react-native-fast-image:*:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- github.com/DylanVann/react-native-fast-image/issues/690nvdExploitThird Party AdvisoryWEB
- github.com/DylanVann/react-native-fast-image/pull/691nvdExploitIssue TrackingThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-REACTNATIVEFASTIMAGE-572228nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-6xhg-q9c8-rj32ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7696ghsaADVISORY
- github.com/DylanVann/react-native-fast-image/commit/4a7cd64f5b0aa40b04d63ccb105ee2b511abe624ghsaWEB
News mentions
0No linked articles in our index yet.