Vulnerabilities/

Feathers exposes internal headers via unencrypted session cookie

Severity:
High

Description

All HTTP request headers are stored in the session cookie, which is signed but not encrypted, exposing internal proxy/gateway headers to clients.

Recommendation

Update the @feathersjs/authentication-oauth package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@feathersjs/authentication-oauth
Anything's wrong? Let us know Last updated on February 23, 2026