Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 Node.js & npm GHSA-r3r9-wp5j-pq5g CVE-2026-62985

request-filtering-agent Denial-of-Service Flaw: Uncaught Exception Can Crash Node.js Apps (CVE-2026-62985)

A flaw in the npm package request-filtering-agent causes a synchronous throw when blocking requests to literal private IPs like 169.254.169.254 or 127.0.0.1, bypassing Node.js error handling and potentially crashing the application. Fixed in version 3.2.1.

Synthesized by AI from 2 sources · updated 2 hours ago

AI summary

A vulnerability has been disclosed in request-filtering-agent, an npm package that implements an http(s).Agent to block outbound requests to private and reserved IP addresses — commonly used as a defense against Server-Side Request Forgery (SSRF). The issue, tracked as CVE-2026-62985 (GHSA-r3r9-wp5j-pq5g), stems from how the library signals rejection of certain requests, and can result in an unhandled exception that terminates the Node.js process. A fix is available in version 3.2.1.

What Happened

request-filtering-agent provides RequestFilteringHttpAgent and RequestFilteringHttpsAgent, which are designed to block connections to private or reserved IP addresses. Prior to version 3.2.1, when a request targeted a literal private-IP host — such as 169.254.169.254 or 127.0.0.1 — the library's createConnection function threw an exception synchronously instead of surfacing the error asynchronously as Node.js's http.request and http.get APIs expect.

Technical Cause

Node.js's http.request and http.get expect connection errors to be delivered asynchronously via the standard req.on('error') event. Because createConnection in affected versions threw synchronously when rejecting a literal private-IP host, this error bypassed req.on('error') entirely and became an uncaught exception at the process level. Note that hostnames resolved via the library's asynchronous DNS lookup path were not affected by this specific error-delivery asymmetry — the issue is limited to literal IP addresses provided directly as the request target. This is classified as CWE-248 (Uncaught Exception).

Why It Matters

An uncaught exception in Node.js can crash the entire process if no global handler is in place, resulting in a denial of service for the application. Since the trigger condition involves a request to a literal private IP address — something an attacker could induce in applications that pass user-supplied URLs or hosts to outbound HTTP requests — this could be leveraged to disrupt availability without requiring authentication or user interaction.

Affected Versions

All versions of request-filtering-agent prior to 3.2.1 are affected. The issue is fixed in version 3.2.1.

Fixes and Mitigation

The vendor has released version 3.2.1, which addresses the synchronous throw behavior. Applications using request-filtering-agent should upgrade to 3.2.1 or later as soon as practical.

Recommended Action

Upgrade request-filtering-agent to version 3.2.1 or later. If immediate upgrading is not possible, ensure global exception handlers are in place for your Node.js process to prevent an uncaught exception from terminating the application, and review any code paths that pass untrusted or user-controlled hosts directly to outbound HTTP requests.

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 7.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Why this score

This issue carries a CVSS score of 7.5 (High), driven primarily by the base score reflecting a network-exploitable, unauthenticated condition with no user interaction required and a high impact on availability. The PatchBriefing score of 4.9 reflects this base severity combined with the absence of known exploitation, no public exploit code, and an available fix. There is no evidence of active exploitation or published exploit code at this time, and EPSS data indicates a low predicted likelihood of near-term exploitation.

Affected versions

request-filtering-agent < 3.2.1
vulnerable
≥ 3.2.1
patched

Reported fixes

The vendor has released version 3.2.1, which addresses the synchronous throw behavior. Applications using request-filtering-agent should upgrade to 3.2.1 or later as soon as practical.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • NVD (NIST) database
Unified report
request-filtering-agent Denial-of-Service Flaw: Uncaught Exception Can Crash Node.js Apps (CVE-2026-62985)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email