CVE-2024-10491: Openjsf Express
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `<>` to preload malicious resources. This vulnerability is especially relevant for dynamic parameters.
Affected products
- Openjsf Express: from 3.0.0, before 3.21.5 (fixed in 3.21.5)
Published 2024-10-29. Last modified 2026-06-17.