Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-11021

19
FAUCET Score

CVE-2020-11021 describes a vulnerability in the NPM @actions/http-client library (versions prior to 1.0.8) where Authorization headers can be inadvertently disclosed to an incorrect domain during specific redirect scenarios. This occurs when an HTTP request with an Authorization header is redirected (302) to a different domain or hostname, causing the header to be sent to the unintended recipient. This vulnerability is rated High severity (CVSS 7.5) due to its network-based attack vector and low attack complexity, potentially leading to a complete compromise of confidentiality (C:H) if sensitive authorization tokens are exposed. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While there is limited community discussion and media coverage, the vulnerability is not listed on the KEV catalog, suggesting it is not currently a widespread threat.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.0.8CPE matchmatch criteria
cpe:2.3:a:http-client_project:http-client:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

6.3MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.74%
Probability of exploitation in next 30 days
EPSS Percentile
75.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0174 is in the 58th percentile among its peer group of 51,551 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: @actions/http-clientFixed in: 1.0.8

Vendor Advisories (1)

npmGHSA-9w6v-m7wp-jwg4medium

Http request which redirect to another hostname do not strip authorization header in @actions/http-client

Apr 29, 2020

References

github.com / actions/http-client/commit/f6aae3dda4f4c9dc0b49737b36007330f78fd53a
PatchThird Party Advisory
github.com / actions/http-client/pull/27
PatchThird Party Advisory
github.com / actions/http-client/security/advisories/GHSA-9w6v-m7wp-jwg4
Third Party Advisory