@node-red/nodes is vulnerable to Denial of Service (DoS)
20
Low Risk
Affected versions of this package are vulnerable to a crash due to uncaught exceptions in the Node-RED HTTP request node. Malformed responses or invalid server data can trigger errors such as a typo in toLowerCase(), missing error handling in request/redirect/response hooks, and insufficient input validation in cookie extraction and digest header construction, causing the entire Node-RED runtime to terminate.
You are affected if you are using a version that falls within the vulnerable range.
@node-red/nodes is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 4.1.2.
Upgrade the @node-red/nodes library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant