CVE-2022-1650: Debian Linux

Critical severity, CVSS 9.3. EPSS: 1.9% chance of exploitation in the next 30 days.

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Eventsource Eventsource: before 1.1.1 (fixed in 1.1.1); from 2.0.0, before 2.0.2 (fixed in 2.0.2)

Published 2022-05-12. Last modified 2026-06-17.