CVE-2026-48022
Description
@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie, and Proxy-Authorization before following a cross-origin redirect, but the origin check compares hostnames only and ignores scheme and port, so credentials are forwarded intact across same-host port changes and HTTPS-to-HTTP downgrades, allowing a co-tenant on an adjacent port or a network-position attacker capable of forging a redirect to capture bearer tokens, session cookies, and proxy credentials and impersonate the victim against the upstream service. This issue is fixed in version 18.1.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@hapi/wrecknpm | < 18.1.2 | 18.1.2 |
Affected products
11- osv-coords10 versionspkg:apk/chainguard/kibana-9.4-iamguardedpkg:apk/chainguard/kibana-9.3pkg:apk/chainguard/kibana-9.3-iamguardedpkg:apk/chainguard/opensearch-dashboards-3pkg:apk/chainguard/opensearch-dashboards-3-fipspkg:apk/chainguard/opensearch-dashboards-3-fips-security-dashboards-pluginpkg:apk/chainguard/opensearch-dashboards-3-security-dashboards-pluginpkg:apk/wolfi/opensearch-dashboards-3pkg:apk/wolfi/opensearch-dashboards-3-security-dashboards-pluginpkg:apk/chainguard/kibana-9.4
< 9.4.2-r3+ 9 more
- (no CPE)range: < 9.4.2-r3
- (no CPE)range: < 9.3.5-r3
- (no CPE)range: < 9.3.5-r3
- (no CPE)range: < 3.8.0-r0
- (no CPE)range: < 3.7.0-r2
- (no CPE)range: < 3.7.0-r0
- (no CPE)range: < 3.7.0-r0
- (no CPE)range: < 3.8.0-r0
- (no CPE)range: < 3.7.0-r0
- (no CPE)range: < 9.4.2-r3
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.