THREAT OPS › Threat News › [NVD] CVE-2026-40895 (HIGH 7.5) — follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization, proxy-authoriza
[NVD] CVE-2026-40895 (HIGH 7.5) — follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization, proxy-authoriza
CVE-2026-40895 CVSS: 7.5 HIGH Published: 2026-04-21T21:16:44.337
follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization, proxy-authorization, and cookie headers (matched by regex at index.js
Indicators of compromise
- CVE-2026-40895cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-40895