{"id":"CVE-2022-33987","aliases":["GHSA-pfrx-2q88-qq97"],"url":"https://o3.security/vulnerability/CVE-2022-33987","summary":"Got allows a redirect to a UNIX socket","details":"The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.","published":"2022-06-18T20:51:12Z","modified":"2026-08-12T03:51:28.831379464Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":{"score":0.02307,"percentile":0.81883,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"got","fixedVersion":"12.1.0"},{"ecosystem":"npm","name":"got","fixedVersion":"11.8.5"}],"fix":{"url":"https://github.com/sindresorhus/got/pull/2047","label":"sindresorhus/got#2047"},"references":[{"type":"WEB","url":"https://github.com/sindresorhus/got/compare/v12.0.3...v12.1.0"},{"type":"WEB","url":"https://github.com/sindresorhus/got/releases/tag/v11.8.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/33xxx/CVE-2022-33987.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-33987"},{"type":"FIX","url":"https://github.com/sindresorhus/got/pull/2047"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:28.831379464Z"}}