CVE-2016-3956: IBM SDK

High severity, CVSS 7.5. EPSS: 6.7% chance of exploitation in the next 30 days.

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.

Affected products

  • IBM SDK: up to and including 1.1.0.20; up to and including 1.2.0.10; up to and including 4.4.1.0
  • Node.js Node.js: version 0.10.0 only; version 0.10.1 only; version 0.10.2 only; version 0.10.3 only; version 0.10.4 only; version 0.10.5 only; …
  • Npmjs Npm: before 2.15.1 (fixed in 2.15.1); from 3.0.0, before 3.8.3 (fixed in 3.8.3)

Published 2016-07-02. Last modified 2026-06-17.