Skip to content

[GHSA-86wf-436m-h424] Resource Exhaustion Denial of Service in http-proxy-agent #7454

Open
Wenxin-Jiang wants to merge 1 commit intoWenxin-Jiang/advisory-improvement-7454from
Wenxin-Jiang-GHSA-86wf-436m-h424
Open

[GHSA-86wf-436m-h424] Resource Exhaustion Denial of Service in http-proxy-agent #7454
Wenxin-Jiang wants to merge 1 commit intoWenxin-Jiang/advisory-improvement-7454from
Wenxin-Jiang-GHSA-86wf-436m-h424

Conversation

@Wenxin-Jiang
Copy link
Copy Markdown

Updates

  • Affected products
  • Severity

Comments
In 0.0.1 and 0.0.2 the Proxy-Authorization injection code this.proxy.auth → req.setHeader('Proxy-Authorization', ...) does not exist — the auth feature was first introduced in 0.1.0.

The suggested change aligns the lower bound with the first release containing the Proxy-Authorization injection, not the initial scaffolding releases that predated the auth feature.

@github-actions github-actions bot changed the base branch from main to Wenxin-Jiang/advisory-improvement-7454 April 20, 2026 14:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant