npm package report

Is http-proxy-agent safe?

2 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
not scored

chance of exploitation in the next 30 days

xyz score
4.5

CyberXYZ composite, out of 10

fig. 01 — GHSA-8w57-jfpm-945m, the advisory selected below

// advisories

GHSA-8w57-jfpm-945m

HIGH

Versions of http-proxy-agent before 2.1.0 are vulnerable to denial of service and uninitialized memory leak when unsanitized options are passed to Buffer. An attacker may leverage these unsanitized options to consume system resources.

Affected
< 2.1.0
Fixed in
2.1.0
Weakness
CWE-400
Published
2019-06-11
Source
github

GHSAreferencereferencereference


// dependencies

4 direct, 3 carrying known advisories, worst HIGH

Sign in for dependency paths and remediation

// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 01:40 UTC. The most recent advisory here was published 2022-01-06. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is http-proxy-agent safe? npm package security report | CyberXYZ