Skip to content
Multiple Vulnerabilities in Ubuntu Follow-Redirects Expose User Data

Multiple Vulnerabilities in Ubuntu Follow-Redirects Expose User Data

First seen 29 Apr 2026, 02:58 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster April 30, 2026 at 02:34 UTC

A series of vulnerabilities were identified in the follow-redirects module affecting Ubuntu 18.04 LTS, 20.04 LTS, and 22.04 LTS. These vulnerabilities include improper handling of sensitive user information during redirects, potentially allowing attackers to expose sensitive data (CVE-2022-0155, CVE-2022-0536). Additionally, issues with URL validation (CVE-2023-26159) and proxy authentication headers (CVE-2024-28849) were discovered, which could lead to phishing attacks and credential exposure. The vulnerabilities primarily affect users of the node-follow-redirects module, which is used for HTTP(S) redirects in Node.js applications. Affected users are advised to update their systems to mitigate these risks. The vulnerabilities were reported on April 28, 2026, with patches available for all affected Ubuntu versions. The issues pose a significant risk to user data security across multiple Ubuntu releases.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 143d ago How this analysis works

Timeline

2022-01-10
CVE-2022-0155 published
2022-02-09
CVE-2022-0536 published
2024-01-02
CVE-2023-26159 published
2024-03-14
CVE-2024-28849 published
2026-04-28
Vulnerabilities reported and patches released

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2022-0155 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed