Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-7339

Опубликовано: 17 июл. 2025
Источник: debian
EPSS Низкий

Описание

on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0` may result in response headers being inadvertently modified when an array is passed to `response.writeHead()`. Users should upgrade to version 1.1.0 to receive a patch. Uses are strongly encouraged to upgrade to `1.1.0`, but this issue can be worked around by passing an object to `response.writeHead()` rather than an array.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-on-headersfixed1.0.2-4package
node-on-headersno-dsatrixiepackage
node-on-headersno-dsabookwormpackage
node-on-headerspostponedbullseyepackage

Примечания

  • https://github.com/jshttp/on-headers/security/advisories/GHSA-76c9-3jph-rj3q

  • https://github.com/jshttp/on-headers/issues/15

  • Fixed by: https://github.com/jshttp/on-headers/commit/c6e384908c9c6127d18831d16ab0bd96e1231867 (v1.1.0)

EPSS

Процентиль: 0%
0.00006
Низкий

Связанные уязвимости

CVSS3: 3.4
ubuntu
3 месяца назад

on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0` may result in response headers being inadvertently modified when an array is passed to `response.writeHead()`. Users should upgrade to version 1.1.0 to receive a patch. Uses are strongly encouraged to upgrade to `1.1.0`, but this issue can be worked around by passing an object to `response.writeHead()` rather than an array.

CVSS3: 3.4
redhat
3 месяца назад

on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0` may result in response headers being inadvertently modified when an array is passed to `response.writeHead()`. Users should upgrade to version 1.1.0 to receive a patch. Uses are strongly encouraged to upgrade to `1.1.0`, but this issue can be worked around by passing an object to `response.writeHead()` rather than an array.

CVSS3: 3.4
nvd
3 месяца назад

on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0` may result in response headers being inadvertently modified when an array is passed to `response.writeHead()`. Users should upgrade to version 1.1.0 to receive a patch. Uses are strongly encouraged to upgrade to `1.1.0`, but this issue can be worked around by passing an object to `response.writeHead()` rather than an array.

CVSS3: 3.4
github
3 месяца назад

on-headers is vulnerable to http response header manipulation

EPSS

Процентиль: 0%
0.00006
Низкий