Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. express
  4. ›
  5. CVE-2024-9266

CVE-2024-9266: Express Open Redirect vulnerability

October 3, 2024 (updated October 9, 2024)

URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0-rc1.

References

  • github.com/advisories/GHSA-jj78-5fmv-mv28
  • github.com/expressjs/express
  • github.com/expressjs/express/compare/3.4.4...3.4.5
  • nvd.nist.gov/vuln/detail/CVE-2024-9266
  • www.herodevs.com/vulnerability-directory/cve-2024-9266

Code Behaviors & Features

Detect and mitigate CVE-2024-9266 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.4.5 before 4.0.0-rc1

Fixed versions

  • 4.0.0-rc1

Solution

Upgrade to version 4.0.0-rc1 or above.

Impact 4.7 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Source file

npm/express/CVE-2024-9266.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:19 +0000.