Multiple Vulnerabilities in Ubuntu Follow-Redirects Expose User Data

Multiple Vulnerabilities in Ubuntu Follow-Redirects Expose User Data

First seen 29 Apr 2026, 02:58 UTC UbuntuLinuxsecurity 86% similarity 57.9

Article Content

Browse articles
ThreatCluster

A series of vulnerabilities were identified in the follow-redirects module affecting Ubuntu 18.04 LTS, 20.04 LTS, and 22.04 LTS. These vulnerabilities include improper handling of sensitive user information during redirects, potentially allowing attackers to expose sensitive data (CVE-2022-0155, CVE-2022-0536). Additionally, issues with URL validation (CVE-2023-26159) and proxy authentication headers (CVE-2024-28849) were discovered, which could lead to phishing attacks and credential exposure. The vulnerabilities primarily affect users of the node-follow-redirects module, which is used for HTTP(S) redirects in Node.js applications. Affected users are advised to update their systems to mitigate these risks. The vulnerabilities were reported on April 28, 2026, with patches available for all affected Ubuntu versions. The issues pose a significant risk to user data security across multiple Ubuntu releases.

Key Points: • Four vulnerabilities identified in the follow-redirects module for Ubuntu. • CVE-2022-0155 and CVE-2022-0536 allow sensitive data exposure during redirects. • CVE-2023-26159 and CVE-2024-28849 increase risks of phishing and credential theft.

ThreatCluster AI

Timeline

2022-01-10
CVE-2022-0155 published
2022-02-09
CVE-2022-0536 published
2024-01-02
CVE-2023-26159 published
2024-03-14
CVE-2024-28849 published
2026-04-28
Vulnerabilities reported and patches released

Community

Browse all →

Tracked Entities in This Story