Loading HuntDB...

GHSA-3787-6prv-h9w3

GitHub Security Advisory

Undici proxy-authorization header not cleared on cross-origin redirect in fetch

✓ GitHub Reviewed LOW Has CVE

Advisory Details

### Impact

Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Proxy-Authorization` headers.

### Patches

This is patched in v5.28.3 and v6.6.1

### Workarounds

There are no known workarounds.

### References

- https://fetch.spec.whatwg.org/#authentication-entries
- https://github.com/nodejs/undici/security/advisories/GHSA-wqq4-5wpv-mx2g

Affected Packages

npm undici
Affected versions: 0 (fixed in 5.28.3)
npm undici
Affected versions: 6.0.0 (fixed in 6.6.1)

Related CVEs

Key Information

GHSA ID
GHSA-3787-6prv-h9w3
Published
February 16, 2024 4:02 PM
Last Modified
May 2, 2024 1:15 PM
CVSS Score
2.5 /10
Primary Ecosystem
npm
Primary Package
undici
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 13, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.