VDB
Sign up
HIGH7.5

GHSA-9xw9-pvgv-6p76

Insufficient Error Handling in http-proxy

Quick fix

GHSA-9xw9-pvgv-6p76 — http-proxy: upgrade to the fixed version with the command below.

npm install http-proxy@0.7.0

Details

Affected versions of `http-proxy` are vulnerable to a denial of service attack, wherein an attacker can force an error which will cause the server to crash.

## Recommendation

Update to version 0.7.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/http-proxy
Introduced in: 0Fixed in: 0.7.0
Fixnpm install http-proxy@0.7.0

References