Skip to main content

Vendor/product archive

openjsf / express CVEs

Beta · best-effort

5 CVEs tagged to openjsf / express0 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2024-10491

Published Oct 29, 2024

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43796

Published Sep 10, 2024

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. Thi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29041

Published Mar 25, 2024

Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerabil…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6393

Published Aug 9, 2017

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1