CVE-2026-27193 affects Feathersjs versions 5.0.39 and below, where HTTP request headers are inadvertently stored in signed but unencrypted session cookies. This vulnerability allows clients to read internal proxy/gateway headers, potentially exposing sensitive infrastructure details like API keys or internal IP addresses, especially when deployed behind reverse proxies. The CVSS score is 5.3 (Medium), indicating a network-based attack with high confidentiality impact but requiring low privileges and high attack complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.0.40CPE matchmatch criteria | cpe:2.3:a:feathersjs:feathers:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.