THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-40895 (HIGH 7.5) — follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization, proxy-authoriza

[NVD] CVE-2026-40895 (HIGH 7.5) — follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization, proxy-authoriza

lownvdPublished 2026-04-21

CVE-2026-40895 CVSS: 7.5 HIGH Published: 2026-04-21T21:16:44.337

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization, proxy-authorization, and cookie headers (matched by regex at index.js

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40895