Low severity2.6NVD Advisory· Published Feb 9, 2022· Updated Jun 17, 2026
CVE-2022-0536
CVE-2022-0536
Description
Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
follow-redirectsnpm | < 1.14.8 | 1.14.8 |
Affected products
4- cpe:2.3:a:follow-redirects_project:follow-redirects:*:*:*:*:*:node.js:*:*Range: <1.14.8
- osv-coords2 versions
< 3.11.14.5-r5+ 1 more
- (no CPE)range: < 3.11.14.5-r5
- (no CPE)range: < 1.14.8
- follow-redirects/follow-redirects/follow-redirectsv5Range: unspecified
Patches
Vulnerability mechanics
References
4- github.com/follow-redirects/follow-redirects/commit/62e546a99c07c3ee5e4e0718c84a6ca127c5c445nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-pw2r-vq6v-hr8cghsaADVISORY
- huntr.dev/bounties/7cf2bf90-52da-4d59-8028-a73b132de0dbnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-0536ghsaADVISORY
News mentions
0No linked articles in our index yet.