Information disclosure in follow-redirects - CVE-2026-40895
Published: April 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in the redirect handling logic in index.js when following cross-domain redirects. A remote attacker can cause a request to be redirected to an attacker-controlled domain to disclose sensitive information.
Custom authentication headers such as API keys or auth tokens may be forwarded to the redirect target, while only authorization, proxy-authorization, and cookie headers are stripped.
Affected software
Optim
Storage Sentinel Anomaly Scan Engine
IBM supplied MQ Advanced container images
IBM MQ Appliance
Platform Navigator in IBM Cloud Pak for Integration (CP4I)
Maximo Scheduler Optimizer
IBM Fusion HCI
IBM MQ Operator
Automation Assets in IBM Cloud Pak for Integration (CP4I)
IBM Sterling Secure Proxy
IBM Sterling External Authentication Server
IBM MQ
IBM Automation Decision Services
IBM DataPower Gateway
Red Hat OpenShift Container Platform
Ubuntu
IBM Security SOAR
node-follow-redirects (Ubuntu package)
How to mitigate CVE-2026-40895
Optim - update to 2.0.0
Storage Sentinel Anomaly Scan Engine - update to 2.3.1
IBM Fusion HCI - update to 2.13.0
IBM MQ Operator - addressed in versions 3.2.26 SC2, 4.0.1 SC2
Automation Assets in IBM Cloud Pak for Integration (CP4I) - addressed in versions 4.0.22-sc2, 4.3.5
IBM Sterling Secure Proxy - addressed in versions 6.1.0.4 iFix01, 6.2.1.2.iFix02
IBM Sterling External Authentication Server - update to 6.1.1.3 iFix01
IBM MQ - addressed in versions 9.2.0.43, 9.3.0.41, 9.4.0.25, 10.0.0.0
IBM supplied MQ Advanced container images - update to 10.0.0.0-r2
IBM MQ Appliance - addressed in versions 9.4.0.25, 9.4.5.2
IBM DataPower Gateway - addressed in versions 10.5.0.22, 10.6.0.10, 11.0.0.2
Platform Navigator in IBM Cloud Pak for Integration (CP4I) - addressed in versions 16.1.0.25, 16.1.3.6
IBM Automation Decision Services - addressed in versions 24.0.0.0.9, 24.0.1.0.8, 25.0.0.0.4
IBM Security SOAR - update to 51.0.10.1
node-follow-redirects (Ubuntu package) - addressed in versions 1.2.4-1ubuntu0.18.04.1~esm2, 1.2.4-1ubuntu0.20.04.1~esm2, 1.14.9+~1.14.1-1ubuntu0.1~esm2, 1.15.6+~1.14.4-1ubuntu0.1~esm1, 1.15.11+~1.14.4-1ubuntu0.1~esm1
Red Hat OpenShift Container Platform - addressed in versions 4.19.35, 4.19.40, 4.20.31, 4.21.26, 4.22.6
Maximo Scheduler Optimizer - addressed in versions 9.0.25, 9.1.14, 9.2.1
External References
Related Security Bulletins
- Information disclosure in follow-redirects
- Platform Navigator and Automation Assets in IBM Cloud Pak for Integration update for follow-redirects
- IBM MQ Appliance update for follow-redirects
- IBM Security SOAR update for follow-redirects
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- IBM Maximo Scheduler Optimizer update for follow-redirects
- IBM Fusion and IBM Fusion HCI update for follow-redirects
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.22
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.19
- Ubuntu update for node-follow-redirects
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in IBM Storage Sentinel Anomaly Scan Engine
- Multiple vulnerabilities in IBM Sterling External Authentication Server
- Multiple vulnerabilities in IBM Sterling Secure Proxy
- IBM MQ update for follow-redirects
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.20
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.21
- IBM DataPower Gateway update for follow-redirects
- IBM Optim update for follow-redirects