VYPR
High severity7.5GHSA Advisory· Published May 30, 2023· Updated Jun 17, 2026

CVE-2023-2968

CVE-2023-2968

Description

A remote attacker can trigger a denial of service in the socket.remoteAddress variable, by sending a crafted HTTP request. Usage of the undefined variable raises a TypeError exception.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
proxynpm
>= 2.0.0, < 2.1.12.1.1

Affected products

4
  • Range: >= 2.0.0, < 2.1.1
  • cpe:2.3:a:proxy_project:proxy:2.0.0:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:proxy_project:proxy:2.0.0:*:*:*:*:node.js:*:*
    • cpe:2.3:a:proxy_project:proxy:2.1.1:*:*:*:*:node.js:*:*
  • ghsa-coords
    Range: >= 2.0.0, < 2.1.1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.