Follow Redirects Project
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-40895 | Hig | 0.42 | 7.5 | 0.00 | Apr 21, 2026 | follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization,… | ||
| CVE-2024-28849 | Med | 0.35 | 6.5 | 0.01 | Mar 14, 2024 | follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which… | ||
| CVE-2022-0155 | Med | 0.35 | 6.5 | 0.02 | Jan 10, 2022 | follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor | ||
| CVE-2022-0536 | Low | 0.10 | 2.6 | 0.01 | Feb 9, 2022 | Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8. |
- risk 0.42cvss 7.5epss 0.00
follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization,…
- risk 0.35cvss 6.5epss 0.01
follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header during cross-domain redirect, but keep the proxy-authentication header which…
- risk 0.35cvss 6.5epss 0.02
follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
- risk 0.10cvss 2.6epss 0.01
Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.