VYPR
Vendor

Follow Redirects Project

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2026-40895HigApr 21, 2026
    risk 0.42cvss 7.5epss 0.00

    follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization,…

  • CVE-2024-28849MedMar 14, 2024
    risk 0.35cvss 6.5epss 0.01

    follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which…

  • CVE-2022-0155MedJan 10, 2022
    risk 0.35cvss 6.5epss 0.02

    follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

  • CVE-2022-0536LowFeb 9, 2022
    risk 0.10cvss 2.6epss 0.01

    Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.