Executive brief
Express is a widely-used web application framework for Node.js that developers rely on to build and serve web applications. A vulnerability in Express's response.links function allows attackers to inject malicious resource references into HTTP Link headers by exploiting improper sanitization of dynamic parameters, potentially leading to malicious resource preloading and other header injection attacks.
Technical details
The vulnerability is a resource injection flaw (CWE-74) in the Express response.links function, stemming from insufficient sanitization of Link header values. Attackers can craft input containing special characters (commas, semicolons, angle brackets) to inject arbitrary resources into the Link header when unsanitized user-controlled data is passed to the function. The attack requires no authentication and is remotely exploitable over the network, affecting all Express versions prior to 4.0.0-rc1. Successful exploitation allows preloading of malicious resources and potential header injection, though the CVSS score of 3.1 (later reported as 4.0 Medium) suggests limited direct impact in many configurations.
Affected products
- Express Express <= 3.21.4
Timeline
- 2024-10-29: disclosed: Vulnerability published
- 2024-10-29: patched: Fix available in version 4.0.0-rc1