📂 Vulnerable Library - express-session-1.15.6.tgz
Simple session middleware for Express
Path to dependency file: /package.json
Findings
| Finding |
Severity |
🎯 CVSS |
Exploit Maturity |
EPSS |
Library |
Type |
Fixed in |
Remediation Available |
Reachability |
| CVE-2025-7339 |
🟠 Medium |
4.6 |
Not Defined |
< 1% |
on-headers-1.0.1.tgz |
Transitive |
N/A |
❌ |
Reachable |
Details
🟠CVE-2025-7339
Vulnerable Library - on-headers-1.0.1.tgz
Execute a listener when a response is about to write headers
Library home page: https://registry.npmjs.org/on-headers/-/on-headers-1.0.1.tgz
Path to dependency file: /package.json
Dependency Hierarchy:
- express-session-1.15.6.tgz (Root Library)
- ❌ on-headers-1.0.1.tgz (Vulnerable Library)
Reachability Analysis
This vulnerability is potentially reachable:
- owasp-nodejs-goat-1.3.0/server.js (Application)
- express-session-1.15.6/index.js (Extension)
-> ❌ on-headers-1.0.1/index.js (Vulnerable Component)
Vulnerability Details
on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions "<1.1.0" may result in response headers being inadvertently modified when an array is passed to "response.writeHead()". Users should upgrade to version 1.1.0 to receive a patch. Uses are strongly encouraged to upgrade to "1.1.0", but this issue can be worked around by passing an object to "response.writeHead()" rather than an array.
Mend Note: The description of this vulnerability differs from MITRE.
Publish Date: Jul 17, 2025 03:47 PM
URL: CVE-2025-7339
Threat Assessment
Exploit Maturity:Not Defined
EPSS:< 1%
Score: 4.6
Suggested Fix
Type: Upgrade version
Origin:
Release Date:
Fix Resolution :
📂 Vulnerable Library - express-session-1.15.6.tgz
Simple session middleware for Express
Path to dependency file: /package.json
Findings
Details
🟠CVE-2025-7339
Vulnerable Library - on-headers-1.0.1.tgz
Execute a listener when a response is about to write headers
Library home page: https://registry.npmjs.org/on-headers/-/on-headers-1.0.1.tgz
Path to dependency file: /package.json
Dependency Hierarchy:
Reachability Analysis
This vulnerability is potentially reachable:
Vulnerability Details
on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions "<1.1.0" may result in response headers being inadvertently modified when an array is passed to "response.writeHead()". Users should upgrade to version 1.1.0 to receive a patch. Uses are strongly encouraged to upgrade to "1.1.0", but this issue can be worked around by passing an object to "response.writeHead()" rather than an array.
Mend Note: The description of this vulnerability differs from MITRE.
Publish Date: Jul 17, 2025 03:47 PM
URL: CVE-2025-7339
Threat Assessment
Exploit Maturity:Not Defined
EPSS:< 1%
Score: 4.6
Suggested Fix
Type: Upgrade version
Origin:
Release Date:
Fix Resolution :