CVE-2024-10491: Openjsf Express

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `<>` to preload malicious resources. This vulnerability is especially relevant for dynamic parameters.

Affected products

  • Openjsf Express: from 3.0.0, before 3.21.5 (fixed in 3.21.5)

Published 2024-10-29. Last modified 2026-06-17.