Information Exposure Affecting goose package, versions *


Severity

Recommended
0.0
medium
0
10

Based on CentOS security rating.

Threat Intelligence

Social Trends
EPSS
0.24% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CENTOS10-GOOSE-17772354
  • published2 Jul 2026
  • disclosed30 Jun 2026

Introduced: 30 Jun 2026

CVE-2026-54673  (opens in a new tab)
CWE-201  (opens in a new tab)

How to fix?

There is no fixed version for Centos:10 goose.

NVD Description

Note: Versions mentioned in the description apply only to the upstream goose package and not the goose package as distributed by Centos. See How to fix? for Centos:10 relevant fixed versions and status.

electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase "authorization", exposing credentials. Other credential-bearing headers — most notably PRIVATE-TOKEN (used by GitLab's personal access token flow) and mixed-case Authorization (used by GitLab's Bearer/OAuth flow) — were not stripped and could be forwarded to an attacker-controlled cross-origin redirect destination. This issue has been fixed in version 9.7.0.

CVSS Base Scores

version 3.1