Description
All HTTP request headers are stored in the session cookie, which is signed but not encrypted, exposing internal proxy/gateway headers to clients.
Recommendation
Update the @feathersjs/authentication-oauth package to the latest compatible version. Followings are version details:
- Affected version(s): <= 5.0.39
- Patched version(s): 5.0.40
References
Could your website be exposed too?
SmartScanner can check your website for Feathers exposes internal headers via unencrypted session cookie and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Feathers has an origin validation bypass via prefix matching - CVE-2026-27192
- Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection - CVE-2026-44496
- Feathers has an open redirect in OAuth callback enables account takeover - CVE-2026-27191
- LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set( - CVE-2026-40190
You might also like:
See something that needs correcting? Let us knowUpdated February 23, 2026


