CVE-2025-7339: Jshttp On-Headers

Low severity, CVSS 3.4. EPSS: 0.2% chance of exploitation in the next 30 days.

on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `<1.1.0` may result in response headers being inadvertently modified when an array is passed to `response.writeHead()`. Users should upgrade to version 1.1.0 to receive a patch. Uses are strongly encouraged to upgrade to `1.1.0`, but this issue can be worked around by passing an object to `response.writeHead()` rather than an array.

Affected products

  • Jshttp On-Headers: before 1.1.0 (fixed in 1.1.0)

Published 2025-07-17. Last modified 2026-06-17.