GHSA-3787-6prv-h9w3
GitHub Security Advisory
Undici proxy-authorization header not cleared on cross-origin redirect in fetch
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
### Impact
Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authorization` headers.
### Patches
This is patched in v5.28.3 and v6.6.1
### Workarounds
There are no known workarounds.
### References
- https://fetch.spec.whatwg.org/#authentication-entries
- https://github.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g
Affected Packages
npm
undici
Affected versions:
0
(fixed in 5.28.3)
npm
undici
Affected versions:
6.0.0
(fixed in 6.6.1)
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: September 13, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.