Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-26159

19
FAUCET Score

CVE-2023-26159 is an Improper Input Validation vulnerability in versions of the 'follow-redirects' package prior to 1.15.4. It arises from the url.parse() function's mishandling of URLs, allowing an attacker to manipulate error conditions to misinterpret hostnames. With a CVSS score of 6.1 (Medium), this vulnerability could enable redirection to malicious sites, potentially leading to information disclosure or phishing attacks, requiring user interaction (UI:R). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.15.4CPE matchmatch criteria
cpe:2.3:a:follow-redirects:follow_redirects:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.80%
Probability of exploitation in next 30 days
EPSS Percentile
52.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0080 is in the 61st percentile among its peer group of 26,234 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (95)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: cbl2 reaper 3.1.1-8 on CBL Mariner 2.0Fixed in: 3.1.1-8
microsoftpatch availablevia msrc
Product: azl3 python-tensorboard 2.11.0-3 on Azure Linux 3.0Fixed in: 2.16.2-1
microsoftpatch availablevia msrc
Product: azl3 python-tensorboard 2.16.2-1 on Azure Linux 3.0Fixed in: 2.16.2-1
microsoftpatch availablevia msrc
Product: 19806-17086Fixed in: 3.1.1-8
microsoftpatch availablevia msrc
Product: 19696-17084Fixed in: 2.16.2-1
microsoftpatch availablevia msrc
Product: 17080-17084Fixed in: 2.16.2-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2.16.2-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2.16.2-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 3.1.1-8
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 3.1.1-8
npmpatch availablevia ghsa
Product: follow-redirectsFixed in: 1.15.4
redhatpatch availablevia redhat_api
Product: multicluster engine for Kubernetes 2.4 for RHEL 8Fixed in: multicluster-engine/console-mce-rhel8:v2.4.5-25
View patch
redhatpatch availablevia redhat_api
Product: multicluster engine for Kubernetes 2.4 for RHEL 8Fixed in: multicluster-engine/multicluster-engine-console-mce-rhel8:v2.4.5-25
View patch
redhatpatch availablevia redhat_api
Product: NETWORK-OBSERVABILITY-1.5.0-RHEL-9Fixed in: network-observability/network-observability-console-plugin-rhel9:v1.5.0-89
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2.9 for RHEL 8Fixed in: rhacm2/console-rhel8:v2.9.4-22
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: openshift4/ose-monitoring-plugin-rhel8:v4.15.0-202402082307.p0.gc3d2272.assembly.stream.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/jaeger-agent-rhel8:1.53.0-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/jaeger-all-in-one-rhel8:1.53.0-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/jaeger-collector-rhel8:1.53.0-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/jaeger-es-index-cleaner-rhel8:1.53.0-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/jaeger-ingester-rhel8:1.53.0-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/jaeger-operator-bundle:1.53.0-15
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/jaeger-query-rhel8:1.53.0-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/jaeger-rhel8-operator:1.53.0-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/opentelemetry-collector-rhel8:0.93.0-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/opentelemetry-operator-bundle:0.93.0-8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/opentelemetry-rhel8-operator:0.93.0-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/opentelemetry-target-allocator-rhel8:0.93.0-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/tempo-gateway-opa-rhel8:1.0.0-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/tempo-gateway-rhel8:1.0.0-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/tempo-operator-bundle:0.8.0-8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/tempo-query-rhel8:0.8.0-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/tempo-rhel8:2.3.1-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/tempo-rhel8-operator:0.8.0-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.5 for RHEL 8Fixed in: openshift-service-mesh/grafana-rhel8:2.5.1-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.5 for RHEL 8Fixed in: openshift-service-mesh/istio-cni-rhel8:2.5.1-8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.5 for RHEL 8Fixed in: openshift-service-mesh/istio-must-gather-rhel8:2.5.1-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.5 for RHEL 8Fixed in: openshift-service-mesh/istio-rhel8-operator:2.5.1-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.5 for RHEL 8Fixed in: openshift-service-mesh/kiali-ossmc-rhel8:1.73.7-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.5 for RHEL 8Fixed in: openshift-service-mesh/kiali-rhel8:1.73.7-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.5 for RHEL 8Fixed in: openshift-service-mesh/kiali-rhel8-operator:1.73.7-4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.5 for RHEL 8Fixed in: openshift-service-mesh/pilot-rhel8:2.5.1-8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.5 for RHEL 8Fixed in: openshift-service-mesh/proxyv2-rhel8:2.5.1-8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.5 for RHEL 8Fixed in: openshift-service-mesh/ratelimit-rhel8:2.5.1-2
View patch
redhatpatch availablevia redhat_api
Product: RHDH-1.1-RHEL-9Fixed in: rhdh/rhdh-hub-rhel9:1.1-97
View patch
redhatpatch availablevia redhat_api
Product: RHEL-9-CNV-4.15Fixed in: container-native-virtualization/kubevirt-console-plugin-rhel9:v4.15.2-383
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-console-rhel9:v4.15.0-57
View patch
redhatpatch availablevia redhat_api
Product: RHODF-4.15-RHEL-9Fixed in: odf4/odf-multicluster-console-rhel9:v4.15.0-54
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.8-RHEL-9Fixed in: openshift-logging/logging-view-plugin-rhel9:v5.8.2-3
View patch
redhatpatch availablevia redhat_api
Product: Cluster Observability Operator 1.0.0Fixed in: cluster-observability-operator/cluster-observability-rhel8-operator:sha256:d186268cdfcf15cc98e28555eef9b0cb6d082e3a9561346f05da62dd74bfdf32
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Openshift distributed tracing 3.1Fixed in: rhosdt/jaeger-es-rollover-rhel8:1.53.0-2
View patch
redhatpatch availablevia redhat_api
Product: Migration Toolkit for Virtualization 2.5Fixed in: migration-toolkit-virtualization/mtv-console-plugin-rhel9:2.5.5-3
View patch
redhatpatch availablevia redhat_api
Product: MTA-6.2-RHEL-8Fixed in: mta/mta-rhel8-operator:6.2.2-3
View patch
redhatpatch availablevia redhat_api
Product: MTA-6.2-RHEL-9Fixed in: mta/mta-hub-rhel9:6.2.2-2
View patch
redhatpatch availablevia redhat_api
Product: MTA-6.2-RHEL-9Fixed in: mta/mta-operator-bundle:6.2.2-5
View patch
redhatpatch availablevia redhat_api
Product: MTA-6.2-RHEL-9Fixed in: mta/mta-pathfinder-rhel9:6.2.2-2
View patch
redhatpatch availablevia redhat_api
Product: MTA-6.2-RHEL-9Fixed in: mta/mta-ui-rhel9:6.2.2-2
View patch
redhatpatch availablevia redhat_api
Product: MTA-6.2-RHEL-9Fixed in: mta/mta-windup-addon-rhel9:6.2.2-3
View patch
redhatpatch availablevia redhat_api
Product: MTA-6.2-RHEL-9Fixed in: mta/mta-ui-rhel9:6.2.3-2
View patch
redhatpatch availablevia redhat_api
Product: MTA-7.0-RHEL-9Fixed in: mta/mta-cli-rhel9:7.0.3-16
View patch
redhatpatch availablevia redhat_api
Product: MTA-7.0-RHEL-9Fixed in: mta/mta-ui-rhel9:7.0.3-13
View patch
redhatpatch availablevia redhat_api
Product: MTR 1.2.4Fixed in: follow-redirects
View patch
ubuntupatch availablevia ubuntu_usn
Product: node-follow-redirects (jammy)Fixed in: 1.14.9+~1.14.1-1ubuntu0.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: node-follow-redirects (focal)Fixed in: 1.2.4-1ubuntu0.20.04.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: node-follow-redirects (bionic)Fixed in: 1.2.4-1ubuntu0.18.04.1~esm1
redhatvendor investigatingvia redhat_api
Product: Cryostat 2Fixed in: follow-redirects
redhatno patchvia redhat_api
Product: Red Hat OpenShift Data Science (RHODS)Fixed in: rhods/odh-dashboard-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift distributed tracing 2Fixed in: rhosdt/jaeger-query-rhel8
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2Fixed in: openshift-service-mesh/kiali-rhel8
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-ui-rhel8
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-db-migration-rhel8
redhatno patchvia redhat_api
Product: OpenShift PipelinesFixed in: openshift-pipelines/pipelines-hub-api-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argo-rollouts-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/console-plugin-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/dashboard-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/traefik-rhel8
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift distributed tracing 2Fixed in: rhosdt/jaeger-all-in-one-rhel8
redhatno patchvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: follow-redirects
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Security 4Fixed in: advanced-cluster-security/rhacs-main-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/kubevirt-console-plugin
redhatend of lifevia redhat_api
Product: Red Hat Decision Manager 7Fixed in: follow-redirects
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: follow-redirects
redhatend of lifevia redhat_api
Product: Red Hat JBoss Data Grid 7Fixed in: follow-redirects
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: console-dashboards-plugin-container
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/nmstate-console-plugin-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/code-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift distributed tracing 2Fixed in: rhosdt/jaeger-collector-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Data Grid 8Fixed in: follow-redirects
redhatend of lifevia redhat_api
Product: Red Hat Process Automation 7Fixed in: follow-redirects
redhatend of lifevia redhat_api
Product: Red Hat build of OptaPlanner 8Fixed in: follow-redirects
redhatend of lifevia redhat_api
Product: Red Hat Advanced Cluster Security 3Fixed in: advanced-cluster-security/rhacs-main-rhel8
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp-system-container

Vendor Advisories (5)

ubuntuUSN-8217-1

follow-redirects vulnerabilities

Apr 28, 2026
microsoft2024-Jun/CVE-2023-26159

CVE-2023-26159

Jun 11, 2024
microsoft2024-Jan/CVE-2023-26159Moderate

Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site potentially leading to information disclosure phishing attacks or other security breaches.

Jan 9, 2024
npmGHSA-jchw-25xp-jwwcmedium

Follow Redirects improperly handles URLs in the url.parse() function

Jan 2, 2024
redhatCVE-2023-26159Moderate

follow-redirects: Improper Input Validation due to the improper handling of URLs by the url.parse()

Jan 2, 2024

References

security.netapp.com / advisory/ntap-20241108-0002
github.com / follow-redirects/follow-redirects/issues/235
ExploitIssue Tracking
github.com / follow-redirects/follow-redirects/pull/236
Issue TrackingPatch
lists.fedoraproject.org / archives/list/[email protected]/message/ZZ425BFKNBQ6AK7I5SAM56TWON5OF2XM
security.snyk.io / vuln/SNYK-JS-FOLLOWREDIRECTS-6141137
ExploitThird Party Advisory