The npm proxy package has a denial-of-service advisory for versions >=2.0.0 and <2.1.1 [S2][S3].
Impact
CVE-2023-2968 affects npm proxy versions 2.0.0 through 2.1.0. Advisory sources describe a denial-of-service condition when crafted HTTP request handling reaches the affected socket.remoteAddress path in a running proxy server [S2][S4]. The fixed version is 2.1.1 [S2][S3].
Root Cause
The issue is tracked as CWE-232, improper handling of undefined values [S1][S2]. The upstream patch guarded use of socket.remoteAddress before adding forwarding headers [S5]. In practical deployment terms, impact depends on whether the affected package is installed in a deployed proxy runtime and receives untrusted traffic.
Covered by FixVibe
FixVibe's GitHub repo scans flag npm projects that depend on proxy releases associated with this advisory, so you can upgrade to 2.1.1 or newer.
Remediation
Upgrade proxy to 2.1.1 or a later maintained release, regenerate the active npm, pnpm, or Yarn lockfile, and rebuild every Node server image, worker, devcontainer, package-manager cache, or CI artifact that installs the dependency [S2][S3]. Keep any deployed proxy endpoint restricted to trusted-network or authenticated access while the rollout is completed.
