Information disclosure in follow-redirects - CVE-2026-40895

 

Information disclosure in follow-redirects - CVE-2026-40895

Published: April 14, 2026


Vulnerability identifier: #VU125981
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40895
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in the redirect handling logic in index.js when following cross-domain redirects. A remote attacker can cause a request to be redirected to an attacker-controlled domain to disclose sensitive information.

Custom authentication headers such as API keys or auth tokens may be forwarded to the redirect target, while only authorization, proxy-authorization, and cookie headers are stripped.


Affected software

follow-redirects
Optim
Storage Sentinel Anomaly Scan Engine
IBM supplied MQ Advanced container images
IBM MQ Appliance
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Maximo Scheduler Optimizer
IBM Fusion HCI
IBM MQ Operator
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
IBM MQ
IBM Automation Decision Services
IBM DataPower Gateway
Red Hat OpenShift Container Platform
Ubuntu
IBM Security SOAR
node-follow-redirects (Ubuntu package)

How to mitigate CVE-2026-40895

Install security update from vendor's website.

follow-redirects - update to 1.16.0
Optim - update to 2.0.0
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
IBM Fusion HCI - update to 2.13.0
IBM MQ Operator - addressed in versions 3.2.26 SC2, 4.0.1 SC2
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.22-sc2, 4.3.5
IBM Sterling Secure Proxy - addressed in versions 6.1.0.4 iFix01, 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
IBM MQ - addressed in versions 9.2.0.43, 9.3.0.41, 9.4.0.25, 10.0.0.0
IBM supplied MQ Advanced container images - update to 10.0.0.0-r2
IBM MQ Appliance - addressed in versions 9.4.0.25, 9.4.5.2
IBM DataPower Gateway - addressed in versions 10.5.0.22, 10.6.0.10, 11.0.0.2
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.25, 16.1.3.6
IBM Automation Decision Services - addressed in versions 24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4
IBM Security SOAR - update to 51.0.10.1
node-follow-redirects (Ubuntu package) - addressed in versions 1.2.4-1ubuntu0.18.04.1~esm2, 1.2.4-1ubuntu0.20.04.1~esm2, 1.14.9+~1.14.1-1ubuntu0.1~esm2, 1.15.6+~1.14.4-1ubuntu0.1~esm1, 1.15.11+~1.14.4-1ubuntu0.1~esm1
Red Hat OpenShift Container Platform - addressed in versions 4.19.35, 4.19.40, 4.20.31, 4.21.26, 4.22.6
Maximo Scheduler Optimizer - addressed in versions 9.0.25, 9.1.14, 9.2.1

External References

Related Security Bulletins