---
cve: "CVE-2026-44979"
severity: "MEDIUM"
cvss: 6.3
epss: "26%"
vendor: "hapijs"
kev: false
exploited: false
published: "2026-07-17 22:17:12"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T01:53:40+02:00"
---

# CVE-2026-44979

> 6.3 MEDIUM · 🧪 PoC

## Beschreibung

@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname, only the Authorization and Cookie headers are stripped, and the standard credential header Proxy-Authorization is forwarded intact to the redirect target, potentially exposing forward-proxy credentials to a host outside the original trust boundary when redirects are enabled through the redirects option or Wreck.defaults({ redirects: ... }). This issue is fixed in version 18.1.1.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- a5b6fac9c684621c1d5733d10a0257697cfea373 (Commit)
- ffeabc4cf97003a0717e41910c4698479b4bbed8 (Commit)

## Referenzen

- <https://github.com/hapijs/wreck/security/advisories/GHSA-vhjm-w67q-g75c>
- <https://github.com/hapijs/wreck/pull/312>
- <https://github.com/hapijs/wreck/commit/a5b6fac9c684621c1d5733d10a0257697cfea373>
- <https://github.com/hapijs/wreck/releases/tag/v18.1.1>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-44979) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
