{"id":"CVE-2024-10491","summary":"Preload arbitrary resources by injecting additional `Link` headers","details":"A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used.\n\nThe issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `\u003c\u003e` to preload malicious resources.\n\nThis vulnerability is especially relevant for dynamic parameters.","aliases":["GHSA-cm5g-3pgc-8rg4"],"modified":"2026-08-12T03:30:35.273014762Z","published":"2024-10-29T16:23:21.219Z","database_specific":{"cwe_ids":["CWE-74"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10491.json","cna_assigner":"HeroDevs"},"references":[{"type":"WEB","url":"https://www.herodevs.com/vulnerability-directory/cve-2024-10491"},{"type":"WEB","url":"https://www.npmjs.com/package/express"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10491.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-10491"},{"type":"PACKAGE","url":"https://github.com/expressjs/express"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/expressjs/express","events":[{"introduced":"d1d3f310e9553fefbaa0e00baac4256af8c3fe27"},{"last_affected":"cb59086305367d9fcd7d63b53cfca1a3e4ef77d7"}],"database_specific":{"extracted_events":[{"introduced":"3.0.0-alpha1"},{"last_affected":"3.21.2"}],"source":"AFFECTED_FIELD"}}],"versions":["3.21.2","3.21.1","3.21.0","3.20.3","3.20.2","3.20.1","3.20.0","3.19.2","3.19.1","3.19.0","3.18.6","3.18.5","3.18.4","3.18.3","3.18.2","3.18.1","3.18.0","3.17.8","3.17.7","3.17.6","3.17.5","3.17.4","3.17.3","3.17.2","3.17.1","3.17.0","3.16.10","3.16.9","3.16.8","3.16.7","3.16.6","3.16.5","3.16.4","3.16.3","3.16.2","3.16.1","3.16.0","3.15.3","3.15.2","3.15.1","3.15.0","3.14.0","3.13.0","3.12.1","3.12.0","3.11.0","3.10.5","3.10.4","3.10.3","3.10.2","3.10.1","3.10.0","3.9.0","3.8.1","3.8.0","3.7.0","3.6.0","3.5.2","3.5.1","3.5.0","3.4.8","3.4.7","3.4.6","3.4.5","3.4.4","3.4.3","3.4.2","3.4.0","3.3.8","3.3.7","3.3.6","3.3.5","3.3.4","3.3.3","3.3.2","3.3.1","3.3.0","3.2.6","3.2.5","3.2.4","3.2.3","3.2.2","3.2.1","3.2.0","3.1.2","3.1.1","3.1.0","3.0.6","3.0.5","3.0.4","3.0.3","3.0.2","3.0.1","3.0.0rc3","3.0.0rc2","3.0.0rc1","3.0.0beta7","3.0.0beta6","3.0.0beta5","3.0.0beta4","3.0.0beta3","3.0.0beta2","3.0.0beta1","3.0.0alpha5","3.0.0alpha4","3.0.0alpha3","3.0.0alpha2","3.0.0alpha1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-10491.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N"}]}