VDB
Sign up
MEDIUM6.1

GHSA-gpvr-g6gh-9mc2

No Charset in Content-Type Header in express

Quick fix

GHSA-gpvr-g6gh-9mc2 — express: upgrade to the fixed version with the command below.

npm install express@3.11.0

Details

Vulnerable versions of express do not specify a charset field in the content-type header while displaying 400 level response messages. The lack of enforcing user's browser to set correct charset, could be leveraged by an attacker to perform a cross-site scripting attack, using non-standard encodings, like UTF-7.

## Recommendation

For express 3.x, update express to version 3.11 or later. For express 4.x, update express to version 4.5 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/express
Introduced in: 0Fixed in: 3.11.0
Fixnpm install express@3.11.0
npm/express
Introduced in: 4.0.0Fixed in: 4.5.0
Fixnpm install express@4.5.0

References