Credential Disclosure Risk in Node.js Module Follow-Redirects

Credential Disclosure Risk in Node.js Module Follow-Redirects

First seen 13 Aug 2026, 03:03 UTC UbuntuLinuxsecurity 76% similarity 57.8

Article Content

Browse articles
ThreatCluster

A vulnerability was discovered in the Node.js module 'follow-redirects' that fails to remove custom authentication headers during cross-domain redirects. This flaw, identified by Dennis Sepede, could allow attackers to obtain sensitive authentication information, leading to credential disclosure. The affected versions include node-follow-redirects 1.15.11 for Ubuntu 26.04 LTS and earlier versions for Ubuntu 24.04, 22.04, 20.04, and 18.04 LTS. Users are advised to update their systems to mitigate this risk. The vulnerability impacts systems using the affected versions of the module, particularly those handling sensitive authentication data. A standard system update is recommended to apply the necessary patches. The issue has been documented in Ubuntu Security Notice USN-8632-1.

Key Points: • A vulnerability in 'follow-redirects' can lead to credential disclosure. • The flaw affects multiple Ubuntu LTS versions, requiring urgent updates. • Users should perform standard system updates to mitigate the risk.

ThreatCluster AI How this analysis works

Timeline

2026-08-12
Vulnerability disclosed by Dennis Sepede
The flaw in 'follow-redirects' was reported, allowing potential credential disclosure through improper header handling.
Ubuntu
2026-08-13
Ubuntu Security Notice USN-8632-1 released
Ubuntu released a security notice detailing the vulnerability and recommended updates for affected systems.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story