| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m4w9-gch5-c2g4 | client-certificate-auth Vulnerable to Open Redirect via Host Header Injection in HTTP-to-HTTPS redirect |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 09 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tgies
Tgies client-certificate-auth |
|
| Vendors & Products |
Tgies
Tgies client-certificate-auth |
Fri, 06 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | client-certificate-auth is middleware for Node.js implementing client SSL certificate authentication/authorization. Versions 0.2.1 and 0.3.0 of client-certificate-auth contain an open redirect vulnerability. The middleware unconditionally redirects HTTP requests to HTTPS using the unvalidated Host header, allowing an attacker to redirect users to arbitrary domains. This vulnerability is fixed in 1.0.0. | |
| Title | client-certificate-auth has an Open Redirect via Host Header Injection in HTTP-to-HTTPS redirect | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-09T15:28:48.992Z
Reserved: 2026-02-04T05:15:41.792Z
Link: CVE-2026-25651
Updated: 2026-02-09T15:19:32.970Z
Status : Awaiting Analysis
Published: 2026-02-06T19:16:09.897
Modified: 2026-02-06T21:57:22.450
Link: CVE-2026-25651
No data.
OpenCVE Enrichment
Updated: 2026-02-09T10:50:12Z
Github GHSA