Junglewise Threat Intelligence

CVE-2026-27193: Feathers authentication-oauth information disclosure via unencrypted session cookie

CVE-2026-27193 · Severity: medium · CVSS 4 · Published 2026-02-19

Technologies: @feathersjs/authentication-oauth (npm). Vendors: Feathers, npm.

Executive brief

Feathers is a JavaScript framework for building real-time APIs and web applications. The OAuth authentication module stores all HTTP request headers—including internal infrastructure details like API keys and service tokens—in session cookies that are signed but not encrypted. An attacker can decode the base64-encoded cookie to read these sensitive internal headers, potentially exposing infrastructure secrets and internal IP addresses in deployments behind proxies or API gateways.

Technical details

The vulnerability is an information disclosure (CWE-200) in the Feathers @feathersjs/authentication-oauth package. The OAuth service stores the complete HTTP headers object in the session cookie via `session.headers = headers`, and these cookies are persisted using cookie-session which base64-encodes but does not encrypt the data. While the cookie is HMAC-signed to prevent tampering, the contents remain readable to anyone who decodes the base64 value. The attack requires network access to intercept or view session cookies; no authentication or user interaction is needed. In deployments behind reverse proxies or API gateways that inject internal headers (e.g., X-Forwarded-For, X-Real-IP, or internal authorization tokens), this exposes sensitive infrastructure details. The vulnerability is fixed in version 5.0.40 and later.

Affected products

  • Feathers @feathersjs/authentication-oauth <= 5.0.39

Timeline

  • 2026-02-19: disclosed: Advisory published on GitHub and OSV
  • 2026-02-19: patched: Fixed in version 5.0.40

References

Related threats