Skip to content

fix(deps): update dependency http-proxy to v1.18.1 [security]#162

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-http-proxy-vulnerability
Open

fix(deps): update dependency http-proxy to v1.18.1 [security]#162
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-http-proxy-vulnerability

Conversation

@renovate
Copy link

@renovate renovate bot commented Aug 6, 2024

This PR contains the following updates:

Package Change Age Confidence
http-proxy 1.18.01.18.1 age confidence

GitHub Vulnerability Alerts

GHSA-6x33-pw7p-hmpq

Versions of http-proxy prior to 1.18.1 are vulnerable to Denial of Service. An HTTP request with a long body triggers an ERR_HTTP_HEADERS_SENT unhandled exception that crashes the proxy server. This is only possible when the proxy server sets headers in the proxy request using the proxyReq.setHeader function.

For a proxy server running on http://localhost:3000, the following curl request triggers the unhandled exception:
curl -XPOST http://localhost:3000 -d "$(python -c 'print("x"*1025)')"

Recommendation

Upgrade to version 1.18.1 or later


Release Notes

http-party/node-http-proxy (http-proxy)

v1.18.1

Compare Source

Merged
  • Skip sending the proxyReq event when the expect header is present #1447
  • Remove node6 support, add node12 to build #1397

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants