CVE-2024-43796: Openjsf Express
Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.
Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.
Affected products
- Openjsf Express: before 4.20.0 (fixed in 4.20.0); version 5.0.0 only
Published 2024-09-10. Last modified 2026-06-17.