VYPR

Wreck

by hapijs

Source repositories

CVEs (1)

  • CVE-2026-44979May 27, 2026
    risk 0.00cvss epss

    ### Impact When `@hapi/wreck` follows a 3xx redirect to a different hostname, only the `Authorization` and `Cookie` headers are stripped. The standard credential header `Proxy-Authorization` is forwarded intact to the redirect target, potentially exposing forward-proxy…