@sap/approuter
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @sap/approuterpage 1 of 1
- CVE-2025-24876HIGHCVSS 8.1EG 8.1✓ Fixed in 16.7.22025-02-11
The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code an attacker can steal the session of the victim by injecting malicious payload causing High impact on c…
- CVE-2026-27690CRITICALCVSS 9.1EG 9.1✓ Fixed in 20.10.02026-07-14
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses …
- CVE-2026-44745HIGHCVSS 8.1EG 8.1✓ Fixed in 21.2.02026-07-14
SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could le…
- CVE-2026-58230HIGHCVSS 7.0EG 7.0✓ Fixed in 23.0.02026-08-11
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled …
Check whether @sap/approuter is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @sap/approuter CVEs against the assets you own.
Start Free Scan →