inngest is vulnerable to Insertion of Sensitive Information Into Sent Data
45
Medium Risk
Affected versions of this package are vulnerable because the OTel exporter transmits the raw signing key in the Authorization Bearer header, instead of a hashed version. This exposes credentials or keys to potential disclosure through logs, proxies, or intermediaries that may have access to request headers.
You are affected if you are using a version that falls within the vulnerable range and use the OTel exporter or extended traces functionality that sends the signing key in outgoing Authorization headers.
inngest is vulnerable to Insertion of Sensitive Information Into Sent Data in versions 0.0.1 - 4.2.4.
Upgrade the inngest library to version 4.2.5 or later.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant