← All CVEs NewScan detects
high

CVE-2024-29041

Express open redirect - res.location()/res.redirect() accept a malformed URL that browsers follow off-site

Severity
high
Affected product
Express
Affected versions
Express < 4.19.2
Fixed in
Express 4.19.2
Added to NewScan
2026-08-02
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Express from its response and reports this CVE when the detected version falls inside the affected range below.

Backfilled 2026-08-02 (docs/todo.md item 1).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →