CVE-2024-29041General(openjsf / express)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a redirect using a user-provided URL Express performs an encode [using `encodeurl`](https://github.com/pillarjs/encodeurl) on the contents before passing it to the `location` header. This can cause malformed URLs to be evaluated in unexpected ways by common redirect allow list implementations in Express applications, leading to an Open Redirect via bypass of a properly implemented allow list. The main method impacted is `res.location()` but this is also called from within `res.redirect()`. The vulnerability is fixed in 4.19.2 and 5.0.0-beta.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601CWE-1286

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • express

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
express

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-05: 1Technical Details · 2026-04-05: 104-05
Signal classification1 categories
General
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • type0press@type0press
    General

    A regex check looks correct. The decoder runs afterward. The SAST tool sees clean dataflow and moves on. This is why OpenAIs new vulnerability detection agent excludes SAST reports from its starting point, and why that design choice matters. The CVE-2024-29041 vulnerability in Express.js (a popular Node.js web framework) allowed attackers to bypass URL allowlists by encoding newlines as %0d%0a, which the regex check saw as benign but the decoder turned into actual newline characters for HTTP header injection. The actual exploit worked like this: an attacker submits https://evil.com%0d%0aLocation:%20https://target.com, the allowlist sees a safe URL, the decoder converts the %0d%0a into real newlines, and the redirect becomes a header injection. This is the most substantive technical explanation of the SAST limitation that a major AI lab has published, appearing in OpenAI's March 6, 2026 blog post announcing Codex Security. https://type0.ai/articles/why-openai-built-codex-security-to-ignore-sast-reports

    Post summary

    The post explains how CVE‑2024‑29041 in Express.js allows attackers to bypass URL allowlists via newline encoding, enabling header injection, but provides no PoC, active exploitation evidence, or patch information.

    0000049
    3 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appopenjsfexpress-node.js-
Appopenjsfexpress5.0.0node.js-
Appopenjsfexpress5.0.0node.js-
Appopenjsfexpress5.0.0node.js-
Appopenjsfexpress5.0.0node.js-
Appopenjsfexpress5.0.0node.js-
Appopenjsfexpress5.0.0node.js-
Appopenjsfexpress5.0.0node.js-
Appopenjsfexpress5.0.0node.js-
Appopenjsfexpress5.0.0node.js-
Appopenjsfexpress5.0.0node.js-

Explore more