This package has limited bug data (2 entries). Check back later or see the package health page for the full signal.

https-proxy-agent known bugs

npm

2 known bugs in https-proxy-agent, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.

2
bugs
Known bugs
SeverityAffectedFixed inTitleStatusSource
mediumany2.2.3
Machine-In-The-Middle in https-proxy-agent
Versions of `https-proxy-agent` prior to 2.2.3 are vulnerable to Machine-In-The-Middle. The package fails to enforce TLS on the socket if the proxy server responds the to the request with a HTTP status different than 200. This allows an attacker with access to the proxy server to intercept unencrypted communications, which may include sensitive information such as credentials. ## Recommendation Upgrade to version 3.0.0 or 2.2.3.
fixedosv:GHSA-pc5p-h8pf-mvwp
criticalany2.2.0
Denial of Service in https-proxy-agent
Versions of `https-proxy-agent` before 2.2.0 are vulnerable to denial of service. This is due to unsanitized options (proxy.auth) being passed to `Buffer()`. ## Recommendation Update to version 2.2.0 or later.
fixedosv:GHSA-8g7p-74h8-hg48
API access

Get this data programmatically \u2014 free, no authentication.

curl https://depscope.dev/api/bugs/npm/https-proxy-agent
https-proxy-agent bugs — known issues per version | DepScope | DepScope