FixVibe

high

Denial of Service Vulnerability in proxy npm Package

The npm proxy package has a denial-of-service advisory for versions >=2.0.0 and <2.1.1. FixVibe GitHub repo scans flag affected proxy versions for CVE-2023-2968 / GHSA-mj6p-3pc9-wf5m.

CVE-2023-2968GHSA-mj6p-3pc9-wf5mGHSA-mj6p-3pc9-wf5mCWE-232

The npm proxy package has a denial-of-service advisory for versions >=2.0.0 and <2.1.1 [S2][S3].

Impact

CVE-2023-2968 affects npm proxy versions 2.0.0 through 2.1.0. Advisory sources describe a denial-of-service condition when crafted HTTP request handling reaches the affected socket.remoteAddress path in a running proxy server [S2][S4]. The fixed version is 2.1.1 [S2][S3].

Root Cause

The issue is tracked as CWE-232, improper handling of undefined values [S1][S2]. The upstream patch guarded use of socket.remoteAddress before adding forwarding headers [S5]. In practical deployment terms, impact depends on whether the affected package is installed in a deployed proxy runtime and receives untrusted traffic.

Covered by FixVibe

FixVibe's GitHub repo scans flag npm projects that depend on proxy releases associated with this advisory, so you can upgrade to 2.1.1 or newer.

Remediation

Upgrade proxy to 2.1.1 or a later maintained release, regenerate the active npm, pnpm, or Yarn lockfile, and rebuild every Node server image, worker, devcontainer, package-manager cache, or CI artifact that installs the dependency [S2][S3]. Keep any deployed proxy endpoint restricted to trusted-network or authenticated access while the rollout is completed.