CVE-2023-26159
Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site, potentially leading to information disclosure, phishing attacks, or other security breaches.
Published:Jan 2, 2024
Last Modified:Nov 3, 2025
EPS:Jan 2, 2024
EPSS Score:0.00072
CVSS Score:7.3
Affected Products
Vendor
Product
Action
Vendor
Follow-redirects
Product
Follow Redirects
Follow-redirects
Follow Redirects
Vendor
Redhat
Product
Acm
Redhat
Acm
Vendor
Redhat
Product
Cluster Observability Operator
Redhat
Cluster Observability Operator
Vendor
Redhat
Product
Container Native Virtualization
Redhat
Container Native Virtualization
Vendor
Redhat
Product
Logging
Redhat
Logging
Vendor
Redhat
Product
Migration Toolkit Applications
Redhat
Migration Toolkit Applications
Vendor
Redhat
Product
Migration Toolkit Runtimes
Redhat
Migration Toolkit Runtimes
Vendor
Redhat
Product
Migration Toolkit Virtualization
Redhat
Migration Toolkit Virtualization
Vendor
Redhat
Product
Multicluster Engine
Redhat
Multicluster Engine
Vendor
Redhat
Product
Network Observ Optr
Redhat
Network Observ Optr
Vendor
Redhat
Product
Openshift
Redhat
Openshift
Vendor
Redhat
Product
Openshift Data Foundation
Redhat
Openshift Data Foundation
Vendor
Redhat
Product
Openshift Distributed Tracing
Redhat
Openshift Distributed Tracing
Vendor
Redhat
Product
Service Mesh
Redhat
Service Mesh
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
