pbojinov / request-ip

A Node.js module for retrieving a request's IP address on the server.
https://npmjs.com/package/request-ip
MIT License
823 stars 102 forks source link

is.js ReDoS Vulnerability #77

Open cbdearborn opened 1 year ago

cbdearborn commented 1 year ago

More info here: https://www.mend.io/vulnerability-database/CVE-2020-26302

soanvig commented 1 year ago

This package has no dependencies, only dev dependencies. How it affects it?

afarah1 commented 1 year ago

This is probably referring to an older version, 2.1.3 used to have that as a dependency. See also https://github.com/newrelic/csec-node-agent/issues/55