Medium severity4.7GHSA Advisory· Published Oct 3, 2024· Updated Jun 17, 2026
CVE-2024-9266
CVE-2024-9266
Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
expressnpm | >= 3.4.5, < 4.0.0-rc1 | 4.0.0-rc1 |
Affected products
9- ghsa-coords8 versionspkg:npm/expresspkg:deb/ubuntu/[email protected]~dfsg-1?arch=source&distro=esm-apps/xenialpkg:deb/ubuntu/[email protected]~dfsg-1?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+~4.17.13-1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]+~cs8.36.26-1?arch=source&distro=oracularpkg:deb/ubuntu/[email protected]+~cs8.36.21-1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]+~cs8.36.26-2?arch=source&distro=plucky
>= 3.4.5, < 4.0.0-rc1+ 7 more
- (no CPE)range: >= 3.4.5, < 4.0.0-rc1
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.