Medium severityGHSA Advisory· Published Jul 17, 2026· Updated Jul 23, 2026
CVE-2026-44979
CVE-2026-44979
Description
@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and Cookie headers are stripped, and the standard credential header Proxy-Authorization is forwarded intact to the redirect target, potentially exposing forward-proxy credentials to a host outside the original trust boundary when redirects are enabled through the redirects option or Wreck.defaults({ redirects: ... }). This issue is fixed in version 18.1.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@hapi/wrecknpm | < 18.1.1 | 18.1.1 |
Affected products
24- osv-coords23 versionspkg:apk/chainguard/kibana-8.17pkg:apk/chainguard/kibana-8.17-bitnamipkg:apk/chainguard/kibana-8.17-iamguardedpkg:apk/chainguard/kibana-8.19pkg:apk/chainguard/kibana-8.19-bitnamipkg:apk/chainguard/kibana-8.19-iamguardedpkg:apk/chainguard/kibana-9.0pkg:apk/chainguard/kibana-9.0-bitnamipkg:apk/chainguard/kibana-9.0-iamguardedpkg:apk/chainguard/kibana-9.1pkg:apk/chainguard/kibana-9.1-iamguardedpkg:apk/chainguard/kibana-9.2pkg:apk/chainguard/kibana-9.2-iamguardedpkg:apk/chainguard/kibana-9.3pkg:apk/chainguard/kibana-9.3-iamguardedpkg:apk/chainguard/kibana-9.4pkg:apk/chainguard/kibana-9.4-iamguardedpkg:apk/chainguard/opensearch-dashboards-3pkg:apk/chainguard/opensearch-dashboards-3-fipspkg:apk/chainguard/opensearch-dashboards-3-fips-security-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-3-security-dashboards-pluginpkg:apk/wolfi/opensearch-dashboards-3pkg:apk/wolfi/opensearch-dashboards-3-security-dashboards-plugin
< 8.17.10-r22+ 22 more
- (no CPE)range: < 8.17.10-r22
- (no CPE)range: < 8.17.10-r22
- (no CPE)range: < 8.17.10-r22
- (no CPE)range: < 8.19.16-r3
- (no CPE)range: < 8.19.16-r3
- (no CPE)range: < 8.19.16-r3
- (no CPE)range: < 9.0.8-r26
- (no CPE)range: < 9.0.8-r26
- (no CPE)range: < 9.0.8-r26
- (no CPE)range: < 9.1.10-r19
- (no CPE)range: < 9.1.10-r19
- (no CPE)range: < 9.2.8-r4
- (no CPE)range: < 9.2.8-r4
- (no CPE)range: < 9.3.5-r0
- (no CPE)range: < 9.3.5-r0
- (no CPE)range: < 9.4.2-r0
- (no CPE)range: < 9.4.2-r0
- (no CPE)range: < 3.8.0-r0
- (no CPE)range: < 3.7.0-r2
- (no CPE)range: < 3.7.0-r0
- (no CPE)range: < 3.7.0-r0
- (no CPE)range: < 3.8.0-r0
- (no CPE)range: < 3.7.0-r0
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-vhjm-w67q-g75cghsaADVISORY
- github.com/hapijs/wreck/commit/a5b6fac9c684621c1d5733d10a0257697cfea373nvdWEB
- github.com/hapijs/wreck/security/advisories/GHSA-vhjm-w67q-g75cnvdWEB
- github.com/nodejs/undici/security/advisories/GHSA-3787-6prv-h9w3ghsaWEB
- github.com/hapijs/wreck/pull/312nvd
- github.com/hapijs/wreck/releases/tag/v18.1.1nvd
News mentions
0No linked articles in our index yet.