{"id":"UBUNTU-CVE-2024-29041","details":"Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a redirect using a user-provided URL Express performs an encode [using `encodeurl`](https://github.com/pillarjs/encodeurl) on the contents before passing it to the `location` header. This can cause malformed URLs to be evaluated in unexpected ways by common redirect allow list implementations in Express applications, leading to an Open Redirect via bypass of a properly implemented allow list. The main method impacted is `res.location()` but this is also called from within `res.redirect()`. The vulnerability is fixed in 4.19.2 and 5.0.0-beta.3.","modified":"2026-02-04T04:13:19.692657Z","published":"2024-03-25T21:15:00Z","related":["USN-7581-1"],"upstream":["CVE-2024-29041"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-29041"},{"type":"REPORT","url":"https://github.com/expressjs/express/security/advisories/GHSA-rv95-896h-c2vc"},{"type":"REPORT","url":"https://github.com/koajs/koa/issues/1800"},{"type":"REPORT","url":"https://github.com/expressjs/express/pull/5539"},{"type":"REPORT","url":"https://github.com/expressjs/express/commit/0867302ddbde0e9463d0564fea5861feb708c2dd"},{"type":"REPORT","url":"https://github.com/expressjs/express/commit/0b746953c4bd8e377123527db11f9cd866e39f94"},{"type":"REPORT","url":"https://expressjs.com/en/4x/api.html#res.location"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-29041"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7581-1"}],"affected":[{"package":{"name":"node-express","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/node-express@4.1.1~dfsg-1ubuntu0.16.04.1~esm1?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1~dfsg-1ubuntu0.16.04.1~esm1"}]}],"versions":["4.1.1~dfsg-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"node-express","binary_version":"4.1.1~dfsg-1ubuntu0.16.04.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-29041.json"}},{"package":{"name":"node-express","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/node-express@4.1.1~dfsg-1ubuntu0.18.04.1~esm1?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.1.1~dfsg-1ubuntu0.18.04.1~esm1"}]}],"versions":["4.1.1~dfsg-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_version":"4.1.1~dfsg-1ubuntu0.18.04.1~esm1","binary_name":"node-express"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-29041.json"}},{"package":{"name":"node-express","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/node-express@4.17.1-2ubuntu0.1~esm1?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.1-2ubuntu0.1~esm1"}]}],"versions":["4.17.1-1","4.17.1-2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"node-express","binary_version":"4.17.1-2ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-29041.json"}},{"package":{"name":"node-express","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/node-express@4.17.3+~4.17.13-1ubuntu0.1~esm1?arch=source&distro=esm-apps/jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.17.3+~4.17.13-1ubuntu0.1~esm1"}]}],"versions":["4.17.1-3","4.17.1+~cs4.17.13-1","4.17.2+~4.17.13-1","4.17.3+~4.17.13-1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"node-express","binary_version":"4.17.3+~4.17.13-1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-29041.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}