This package has limited bug data (2 entries). Check back later or see the package health page for the full signal.
https-proxy-agent known bugs
npm2 known bugs in https-proxy-agent, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.
2
bugs
Known bugs
| Severity | Affected | Fixed in | Title | Status | Source |
|---|---|---|---|---|---|
| medium | any | 2.2.3 | Machine-In-The-Middle in https-proxy-agent Versions of `https-proxy-agent` prior to 2.2.3 are vulnerable to Machine-In-The-Middle. The package fails to enforce TLS on the socket if the proxy server responds the to the request with a HTTP status different than 200. This allows an attacker with access to the proxy server to intercept unencrypted communications, which may include sensitive information such as credentials.
## Recommendation
Upgrade to version 3.0.0 or 2.2.3. | fixed | osv:GHSA-pc5p-h8pf-mvwp |
| critical | any | 2.2.0 | Denial of Service in https-proxy-agent Versions of `https-proxy-agent` before 2.2.0 are vulnerable to denial of service. This is due to unsanitized options (proxy.auth) being passed to `Buffer()`.
## Recommendation
Update to version 2.2.0 or later. | fixed | osv:GHSA-8g7p-74h8-hg48 |
API access
Get this data programmatically \u2014 free, no authentication.
curl https://depscope.dev/api/bugs/npm/https-proxy-agent