Executive brief
A vulnerability in a popular web request library can cause sensitive login information to be sent to unauthorized third-party websites. When a website redirects a user's request to a different domain, the library fails to remove custom security tokens or API keys from the request. This could allow an attacker to intercept these credentials and gain unauthorized access to user accounts or services.
Technical details
The follow-redirects library, a dependency for the widely used axios client, contains an information exposure vulnerability. When handling cross-domain redirects (HTTP 301, 302, 307, or 308), the library's header-stripping logic only targets standard 'authorization', 'proxy-authorization', and 'cookie' headers via a hardcoded regular expression. Custom authentication headers such as 'X-API-Key' or 'X-Auth-Token' are forwarded verbatim to the new domain. An attacker who controls a redirect target can capture these sensitive credentials. This issue is fixed in version 1.16.0.
Affected products
- follow-redirects follow-redirects <= 1.15.11
Timeline
- 2026-03-20: other: Vulnerability found via source code review
- 2026-04-13: patched: Fix published in version 1.16.0
- 2026-04-14: advisory: GitHub Advisory GHSA-r4q5-vmmm-2653 published