CVE-2024-43796: Openjsf Express

Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.

Affected products

  • Openjsf Express: before 4.20.0 (fixed in 4.20.0); version 5.0.0 only

Published 2024-09-10. Last modified 2026-06-17.