Medium severity4.0NVD Advisory· Published Oct 29, 2024· Updated Jun 17, 2026
CVE-2024-10491
CVE-2024-10491
Description
A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used.
The issue arises from improper sanitization in Link header values, which can allow a combination of characters like ,, ;, and <> to preload malicious resources.
This vulnerability is especially relevant for dynamic parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
expressnpm | < 4.0.0-rc1 | 4.0.0-rc1 |
Affected products
10- osv-coords8 versionspkg:deb/ubuntu/[email protected]~dfsg-1?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]~dfsg-1?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+~4.17.13-1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]+~cs8.36.21-1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]+~cs8.36.26-1?arch=source&distro=oracularpkg:deb/ubuntu/[email protected]+~cs8.36.26-2?arch=source&distro=pluckypkg:npm/express
>= 0+ 7 more
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: < 4.0.0-rc1
Patches
Vulnerability mechanics
References
4- www.herodevs.com/vulnerability-directory/cve-2024-10491nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-cm5g-3pgc-8rg4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-10491ghsaADVISORY
- github.com/expressjs/express/issues/6222ghsaWEB
News mentions
0No linked articles in our index yet.