Intel

AIKIDO-2026-564744

@whatwg-node/fetch is vulnerable to Information Disclosure

Information DisclosureGHSA-5vr3-24rx-7h7x Published Yesterday

75

High Risk

This Affects:

JS@whatwg-node/fetch
0.0.1 - 0.12.0
Fixed in 0.12.1
Are you affected? Scan for Free

TL;DR

The Node HTTP path in @whatwg-node/fetch builds the redirect request by reusing the original request's Headers object, so Authorization, Cookie, Cookie2, Proxy-Authorization, and an explicit Host header are sent to a different origin on a cross-origin redirect, leaking credentials to the redirect target. An https to http downgrade redirect leaks them too, since the scheme is part of the origin, while same-origin redirects are unaffected and the caller's original Headers object is not modified. The patch rebuilds the redirect request's headers, strips these headers on cross-origin hops, and rejects cors-mode cross-origin redirects whose target URL embeds credentials.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@whatwg-node/fetch is vulnerable to Information Disclosure in versions 0.0.1 - 0.12.0.

How to fix this

Upgrade the @whatwg-node/fetch library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform