Known vulnerabilities in follow-redirects
Vendor:
follow-redirects
Software:
follow-redirects
Software CPE:
cpe:2.3:a:follow-redirects:follow-redirects:*:*:*:*:*:nodejs:*:*
Website:
https://github.com/follow-redirects
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
6.9
Breakdown by Severity Chart
1.16.0
1.15.11
1.15.10
1.15.9
1.15.8
1.15.7
1.15.6
1.15.5
1.15.4
1.15.3
1.15.2
1.15.1
1.15.0
1.14.9
1.14.8
1.14.7
1.14.6
1.14.5
1.14.4
1.14.3
1.14.2
1.14.1
1.14.0
1.13.3
1.13.2
1.13.1
1.13.0
1.12.1
1.12.0
1.11.0
1.10.0
1.9.1
1.9.0
1.8.1
1.8.0
1.7.0
1.6.1
1.6.0
1.5.10
1.5.9
1.5.8
1.5.7
1.5.6
1.5.5
1.5.4
1.5.3
1.5.2
1.5.1
1.5.0
1.4.1
1.4.0
1.3.0
1.2.6
1.2.5
1.2.4
1.2.3
1.2.2
1.2.1
1.2.0
1.1.0
1.0.0
0.3.0
0.2.0
0.1.0
0.0.7
0.0.6
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU125981 - Exposure of sensitive information to an unauthorized actor CVE-2026-40895 |
CWE-200 | Medium | 1.16.0 | 14.04.2026 |
SB20260414106 SB2026062434 SB20260625284 and 7 more |
||
| #VU87551 - Exposure of sensitive information to an unauthorized actor CVE-2024-28849 |
CWE-200 | Low | 1.15.6 | 15.03.2024 |
SB2024031508 SB2024031517 SB2024040365 and 59 more |
||
| #VU85369 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2023-26159 |
CWE-601 | Low | 1.15.4 | 15.01.2024 |
SB2024011510 SB2024011517 SB2024011864 and 53 more |
||
| #VU61669 - Exposure of sensitive information to an unauthorized actor CVE-2022-0155 |
CWE-200 | Low | 1.14.7 | 28.03.2022 |
SB2022032840 SB2022032843 SB2022071505 and 32 more |
||
| #VU61668 - Exposure of sensitive information to an unauthorized actor CVE-2022-0536 |
CWE-200 | Low | 1.14.8 | 28.03.2022 |
SB2022032841 SB2022032843 SB2022042561 and 27 more |