follow-redirects: Auth Header Leak via Cross-Domain Redirects (1.15.x)
CVE-2026-40895 Published on April 21, 2026

follow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect Targets
follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redirect (301/302/307/308), follow-redirects only strips authorization, proxy-authorization, and cookie headers (matched by regex at index.js). Any custom authentication header (e.g., X-API-Key, X-Auth-Token, Api-Key, Token) is forwarded verbatim to the redirect target. This vulnerability is fixed in 1.16.0.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-40895 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
NONE
Availability Impact:
NONE

Weakness Types

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2026-40895 has been classified to as an Information Disclosure vulnerability or weakness.

Improper Removal of Sensitive Information Before Storage or Transfer

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.


Products Associated with CVE-2026-40895

Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

follow-redirects: Red Hat Cryostat 4 on RHEL 9: Red Hat Cluster Observability Operator 1.5.0: Red Hat Cluster Observability Operator 1.5.0: Red Hat Cluster Observability Operator 1.5.0: Red Hat Cluster Observability Operator 1.5.0: Red Hat multicluster engine for Kubernetes 2.1: Red Hat multicluster engine for Kubernetes 2.11.0: Red Hat multicluster engine for Kubernetes 2.6: Red Hat multicluster engine for Kubernetes 2.8: Red Hat multicluster engine for Kubernetes 2.9: Red Hat Network Observability (NETOBSERV) 1.11.1: Red Hat Network Observability (NETOBSERV) 1.11.1: Red Hat Advanced Cluster Management for Kubernetes 2.14: Red Hat Advanced Cluster Management for Kubernetes 2.15: Red Hat Advanced Cluster Management for Kubernetes 2.16: Red Hat Advanced Cluster Security 4.9: Red Hat Advanced Cluster Security for Kubernetes 4.10: Red Hat Ansible Automation Platform 2.5: Red Hat Developer Hub 1.8: Red Hat Developer Hub 1.9: Red Hat Discovery 2: Red Hat Migration Toolkit 1.8: Red Hat Migration Toolkit for Applications 8.1: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 3.3: Red Hat OpenShift AI 3.3: Red Hat OpenShift AI 3.3: Red Hat OpenShift Container Platform 4.17: Red Hat OpenShift Container Platform 4.18: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.19: Red Hat OpenShift Container Platform 4.20: Red Hat OpenShift Container Platform 4.20: Red Hat OpenShift Container Platform 4.21: Red Hat OpenShift Container Platform 4.21: Red Hat OpenShift Container Platform 4.22: Red Hat OpenShift Dev Spaces 3.28: Red Hat OpenShift Dev Spaces 3.28: Red Hat OpenShift Dev Spaces 3.28: Red Hat OpenShift Dev Spaces 3.28: Red Hat OpenShift Service Mesh 2.6: Red Hat OpenShift Service Mesh 2.6: Red Hat OpenShift Service Mesh 3.0: Red Hat OpenShift Service Mesh 3.0: Red Hat OpenShift Service Mesh 3.1: Red Hat OpenShift Service Mesh 3.1: Red Hat OpenShift Service Mesh 3.2: Red Hat OpenShift Service Mesh 3.2: Red Hat OpenShift Service Mesh 3.3: Red Hat OpenShift Service Mesh 3.3: Red Hat Quay 3.1: Red Hat Quay 3.12: Red Hat Quay 3.14: Red Hat Quay 3.15: Red Hat Quay 3.16: Red Hat Quay 3.17: Red Hat Quay 3.9: Red Hat Cryostat 4: Red Hat Cryostat 4: Red Hat Gatekeeper 3: Red Hat Migration Toolkit for Applications 8: Red Hat Migration Toolkit for Virtualization: Red Hat Migration Toolkit for Virtualization: Red Hat Node HealthCheck Operator: Red Hat Node HealthCheck Operator: Red Hat Node HealthCheck Operator: Red Hat OpenShift Lightspeed: Red Hat OpenShift Lightspeed: Red Hat OpenShift Lightspeed: Red Hat OpenShift Pipelines: Red Hat OpenShift Pipelines: Red Hat OpenShift Pipelines: Red Hat OpenShift Pipelines: Red Hat OpenShift Service Mesh 3: Red Hat OpenShift Service Mesh 3: Red Hat 3scale API Management Platform 2: Red Hat 3scale API Management Platform 2: Red Hat 3scale API Management Platform 2: Red Hat 3scale API Management Platform 2: Red Hat 3scale API Management Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat build of Apache Camel - HawtIO 4: Red Hat build of Apicurio Registry 2: Red Hat build of Apicurio Registry 3: Red Hat build of Apicurio Registry 3: Red Hat Build of Podman Desktop: Red Hat Build of Podman Desktop - Tech Preview: Red Hat Ceph Storage 9: Red Hat Connectivity Link 1: Red Hat Data Grid 8: Red Hat Developer Hub: Red Hat Edge Manager 1: Red Hat Edge Manager 1: Red Hat Edge Manager 1: Red Hat Edge Manager 1: Red Hat Enterprise Linux 8: Red Hat Enterprise Linux 8: Red Hat Enterprise Linux 9: Red Hat Enterprise Linux 9: Red Hat Enterprise Linux AI (RHEL AI) 3: Red Hat Enterprise Linux AI (RHEL AI) 3: Red Hat Enterprise Linux AI (RHEL AI) 3: Red Hat Fuse 7: Red Hat Hardened Images: Red Hat Hardened Images: Red Hat Hardened Images: Red Hat JBoss Enterprise Application Platform 7: Red Hat JBoss Enterprise Application Platform 8: Red Hat JBoss Enterprise Application Platform Expansion Pack: Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift Container Platform 4: Red Hat OpenShift Container Platform 4: Red Hat OpenShift Container Platform 4: Red Hat OpenShift Container Platform 4: Red Hat OpenShift Container Platform 4: Red Hat Openshift Data Foundation 4: Red Hat Openshift Data Foundation 4: Red Hat Openshift Data Foundation 4: Red Hat OpenShift distributed tracing 3: Red Hat OpenShift GitOps: Red Hat OpenShift GitOps: Red Hat OpenShift Virtualization 4: Red Hat OpenShift Virtualization 4: Red Hat Process Automation 7: Red Hat Satellite 6: Red Hat Satellite 6: Red Hat Satellite 6: Red Hat Trusted Artifact Signer: Red Hat Trusted Profile Analyzer: Red Hat Self-service automation portal 2: Red Hat streams for Apache Kafka 2: Red Hat streams for Apache Kafka 3:

Exploit Probability

EPSS
0.49%
Percentile
39.10%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.