Executive brief
Feathers is a JavaScript framework for building real-time APIs and web applications. The OAuth authentication module stores all HTTP request headers—including internal infrastructure details like API keys and service tokens—in session cookies that are signed but not encrypted. An attacker can decode the base64-encoded cookie to read these sensitive internal headers, potentially exposing infrastructure secrets and internal IP addresses in deployments behind proxies or API gateways.
Technical details
The vulnerability is an information disclosure (CWE-200) in the Feathers @feathersjs/authentication-oauth package. The OAuth service stores the complete HTTP headers object in the session cookie via `session.headers = headers`, and these cookies are persisted using cookie-session which base64-encodes but does not encrypt the data. While the cookie is HMAC-signed to prevent tampering, the contents remain readable to anyone who decodes the base64 value. The attack requires network access to intercept or view session cookies; no authentication or user interaction is needed. In deployments behind reverse proxies or API gateways that inject internal headers (e.g., X-Forwarded-For, X-Real-IP, or internal authorization tokens), this exposes sensitive infrastructure details. The vulnerability is fixed in version 5.0.40 and later.
Affected products
- Feathers @feathersjs/authentication-oauth <= 5.0.39
Timeline
- 2026-02-19: disclosed: Advisory published on GitHub and OSV
- 2026-02-19: patched: Fixed in version 5.0.40