VDB
Sign up
HIGH

GHSA-8w57-jfpm-945m

Denial of Service in http-proxy-agent

Quick fix

GHSA-8w57-jfpm-945m — http-proxy-agent: upgrade to the fixed version with the command below.

npm install http-proxy-agent@2.1.0

Details

Versions of `http-proxy-agent` before 2.1.0 are vulnerable to denial of service and uninitialized memory leak when unsanitized options are passed to `Buffer`. An attacker may leverage these unsanitized options to consume system resources.

## Recommendation

Update to version 2.1.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/http-proxy-agent
Introduced in: 0Fixed in: 2.1.0
Fixnpm install http-proxy-agent@2.1.0

References