Affected versions of http-proxy are vulnerable to a denial of service attack, wherein an attacker can force an error which will cause the server to crash. Upstream issue: https://github.com/nodejitsu/node-http-proxy/pull/101 External references: https://nodesecurity.io/advisories/323
Created nodejs-http-proxy tracking bugs for this issue: Affects: fedora-all [bug 1591874]
May I know why you think given https://github.com/nodejitsu/node-http-proxy/pull/101 patch is not already present in Fedora? The current Fedora release for this package is nodejs-http-proxy-1.16.2-5.fc28.noarch and is based on upstream release 1.16.2 which got released in December 2016. The patch you given in description is already merged in upstream since long time.
(In reply to Parag Nemade from comment #2) > May I know why you think given > https://github.com/nodejitsu/node-http-proxy/pull/101 patch is not already > present in Fedora? > > The current Fedora release for this package is > nodejs-http-proxy-1.16.2-5.fc28.noarch and is based on upstream release > 1.16.2 which got released in December 2016. > > The patch you given in description is already merged in upstream since long > time. Hi, This definitely looks like an error, I'll change the status to notaffected and close the associated tracking bug. Thanks for the info!