VDB
Sign up
CRITICAL9.1

GHSA-8g7p-74h8-hg48

Denial of Service in https-proxy-agent

Quick fix

GHSA-8g7p-74h8-hg48 — https-proxy-agent: upgrade to the fixed version with the command below.

npm install https-proxy-agent@2.2.0

Details

Versions of `https-proxy-agent` before 2.2.0 are vulnerable to denial of service. This is due to unsanitized options (proxy.auth) being passed to `Buffer()`.

## Recommendation

Update to version 2.2.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/https-proxy-agent
Introduced in: 0Fixed in: 2.2.0
Fixnpm install https-proxy-agent@2.2.0

References