What is CVE-2026-49473?
CVE-2026-49473 is a vulnerability in @cedar-policy/authorization-for-expressjs middleware prior to version 0.3.0 that allows bypassing authorization checks due to incorrect mapping of HTTP requests. This can lead to unauthorized access in Express.js applications, and upgrading to version 0.3.0 or later is recommended.
Azərbaycanca: CVE-2026-49473 @cedar-policy/authorization-for-expressjs middleware-in 0.3.0-dən əvvəlki versiyalarında HTTP sorğularının səhv mapping edilməsi səbəbindən icazə yoxlamasından yan keçməyə imkan verən zəiflikdir. Bu, Express.js tətbiqlərində səlahiyyətsiz girişə səbəb ola bilər, dərhal 0.3.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of @cedar-policy/authorization-for-expressjs middleware are affected by CVE-2026-49473?
Versions prior to 0.3.0 are affected.
How can CVE-2026-49473 be mitigated?
Upgrading to version 0.3.0 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.