Vulnerability Database

309,130

Total vulnerabilities in the database

CVE-2025-7339

on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions <1.1.0 may result in response headers being inadvertently modified when an array is passed to response.writeHead(). Users should upgrade to version 1.1.0 to receive a patch. Uses are strongly encouraged to upgrade to 1.1.0, but this issue can be worked around by passing an object to response.writeHead() rather than an array.

CVSS v3:

  • Severity: Unknown
  • Score:
  • AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

CWEs: