PT-2026-34171 · Npm+2 · Follow-Redirects+2

CVE-2026-40895

·

Published

2026-03-20

·

Updated

2026-08-31

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions follow-redirects versions prior to 1.16.0
Description When an HTTP request follows a cross-domain redirect (301, 302, 307, or 308), the software only removes authorization, proxy-authorization, and cookie headers. Any custom authentication headers, such as X-API-Key, X-Auth-Token, Api-Key, or Token, are forwarded verbatim to the redirect target.
Recommendations Update to version 1.16.0.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09333
CVE-2026-40895
GHSA-R4Q5-VMMM-2653
USN-8632-1

Affected Products

Linuxmint
Ubuntu
Follow-Redirects