ThreatCluster

Multiple CVEs Identified for Proxy-Authorization Header Vulnerabilities

First seen 18 Feb 2026, 09:15 UTC Api.Msrc.Microsoft 48

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been identified related to the Proxy-Authorization header in the Undici library. CVE-2024-30260, published on April 4, 2024, and CVE-2024-28849, published on March 14, 2024, both allow for potential security issues due to improper handling of authorization headers across different hosts. Affected systems may be at risk if these vulnerabilities are not addressed.

Timeline

2024-03-14
CVE-2024-28849 published
2024-04-04
CVE-2024-30260 published
2026-02-18
Information published about both CVEs