VYPR
Moderate severityNVD Advisory· Published Feb 6, 2026· Updated Feb 9, 2026

client-certificate-auth has an Open Redirect via Host Header Injection in HTTP-to-HTTPS redirect

CVE-2026-25651

Description

client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Versions 0.2.1 and 0.3.0 of client-certificate-auth contain an open redirect vulnerability. The middleware unconditionally redirects HTTP requests to HTTPS using the unvalidated Host header, allowing an attacker to redirect users to arbitrary domains. This vulnerability is fixed in 1.0.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
client-certificate-authnpm
>= 0.2.1, < 1.0.01.0.0

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.