OVERVIEW CVE-2026-40895 affects the follow-redirects library, a widely-used Node.js module that automatically handles HTTP redirects as a drop-in replacement for native http and https modules. Prior to version 1.16.0, the library fails to strip custom authentication headers such as X-API-Key, X-Auth-Token, Api-Key, and Token when processing cross-domain redirects (301/302/307/308 status codes). While the library removes standard authorization headers, custom authentication credentials are inadvertently forwarded to untrusted redirect targets. SEVERITY This vulnerability carries a CVSS v3.1 score of 7.5 (HIGH) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, allowing any unauthenticated threat actor to exploit this condition by hosting a malicious redirect target. The primary impact is a high confidentiality breach, as sensitive authentication tokens and API keys can be harvested from requests to cross-domain redirects. EXPLOITATION STATUS There is no evidence of active exploitation. The EPSS score of 0.0005 indicates minimal exploitation probability, and the vulnerability does not appear on the KEV catalog or the hot list, suggesting limited community attention or adversarial activity. Mitigation is straightforward through immediate upgrade to version 1.16.0 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.16.0CPE matchmatch criteria | cpe:2.3:a:follow-redirects_project:follow-redirects:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.