CVE-2025-7339

ADVISORY - github

Summary

Impact

A bug in on-headers versions < 1.1.0 may result in response headers being inadvertently modified when an array is passed to response.writeHead()

Patches

Users should upgrade to 1.1.0

Workarounds

Uses are encouraged to upgrade to 1.1.0, but this issue can be worked around by passing an object to response.writeHead() rather than an array.

EPSS Score: 0.00036 (0.110)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Improper Handling of Unexpected Data Type

ADVISORY - github

Improper Handling of Unexpected Data Type

ADVISORY - gitlab

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Improper Handling of Unexpected Data Type

OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities

ADVISORY - redhat

Improper Handling of Unexpected Data Type


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in