Junglewise Threat Intelligence

CVE-2026-48022: hapijs @hapi/wreck credential leak in cross-origin redirects

CVE-2026-48022 · Severity: medium · CVSS 6.5 · Published 2026-07-17

Vendors: npm, Hapi.

Executive brief

@hapi/wreck is a software tool used by developers to make web requests. A security flaw in how it handles web redirects could allow an attacker to steal sensitive login information, such as session cookies or security tokens. This happens because the tool may accidentally send your private credentials to an untrusted server if it is redirected to a different port or an unencrypted connection on the same host.

Technical details

A vulnerability exists in @hapi/wreck prior to version 18.1.2 where the library's origin validation logic only compares hostnames during HTTP redirects. It fails to account for the URI scheme and port number. Consequently, sensitive headers such as 'Authorization', 'Cookie', and 'Proxy-Authorization' are forwarded during HTTPS-to-HTTP downgrades or redirects to different ports on the same host. An attacker positioned on the network or a co-tenant on the same host could exploit this to capture credentials and impersonate users. The fix implements a full-origin comparison (scheme, host, and port) consistent with the WHATWG Fetch standard.

Affected products

  • hapijs wreck < 18.1.2

Timeline

  • 2026-05-20: patched: Fix committed and version 18.1.2 released
  • 2026-07-17: disclosed: CVE published to NVD

References

Related threats