CVE-2024-9266: Expressjs Express

Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0.

Affected products

  • Expressjs Express: from 3.4.5, before 4.0.0 (fixed in 4.0.0)

Published 2024-10-03. Last modified 2026-06-17.