VDB
Sign up
HIGH7.5

GHSA-mj6p-3pc9-wf5m

proxy denial of service vulnerability

Quick fix

GHSA-mj6p-3pc9-wf5m — proxy: upgrade to the fixed version with the command below.

npm install proxy@2.1.1

Details

A remote attacker can trigger a denial of service in the `socket.remoteAddress` variable, by sending a crafted HTTP request. Usage of the undefined variable raises a TypeError exception.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/proxy
Introduced in: 2.0.0Fixed in: 2.1.1
Fixnpm install proxy@2.1.1

References